Re: [Buildroot] [PATCH 1/1] package/samba4: security bump version to 4.24.5

Titouan Christophe via buildroot <[email protected]>
Newsgroups net.busybox.buildroot
Message-ID <[email protected]>

On 28/07/26 19:36, Bernd Kuhls wrote:
> https://www.samba.org/samba/history/samba-4.24.5.html
>
> This is a security release in order to address the following defects:
>
> o CVE-2026-6949:
>    TSIG packet with name compression can crash DNS
>
>     Incorrect size calculations when a TSIG record contains
>     compressed names can lead to a large out-of-bounds write
>     causing the server to crash.
>
>     https://www.samba.org/samba/security/CVE-2026-6949.html
>
> o CVE-2026-58216:
>    An authenticated user could possibly crash a KDC process
>
>     A kpasswd packet that contains malformed ASN.1 might cause
>     the server to access 6 bytes of unallocated memory. This
>     memory is not exposed to the user, but in some
>     circumstances the server could crash.
>
>     https://www.samba.org/samba/security/CVE-2026-58216.html
>
> o CVE-2026-58218:
>    DNS signing DoS via TKEY name cache exhaustion
>
>     An unauthenticated user can repeatedly register names TKEY
>     names, which floods a cache causing legitimate TKEYs to be
>     expunged. This can practically block the use DNS TSIG
>     signing.
>
>     https://www.samba.org/samba/security/CVE-2026-58218.html
>
> o CVE-2026-58221:
>    Samba AD authenticated LDAP access domain takeover
>
>     Samba AD low-privilege authenticated LDAP access allows
>     modifications to internal LDB special DNs, which permits a
>     domain takeover.
>
>     https://www.samba.org/samba/security/CVE-2026-58221.html
>
> o CVE-2026-58222:
>    Samba AD LDAP Compare filter injection and trusted-request
>     confusion disclose protected attributes
>
>     An ordinary authenticated domain user can bypass access
>     checks and query confidential Active Directory attributes
>     (such as KDS root keys) via LDAP Compare requests. Due to a
>     filter injection flaw and trusted execution context, the
>     LDAP Compare operation can be turned into a
>     protected-attribute disclosure oracle.
>
>     https://www.samba.org/samba/security/CVE-2026-58222.html
>
> o CVE-2026-58224:
>    The CTDB protocol has bounds checking issues
>
>     CTDB fails to do integrity checking of received packets.
>     This includes failure to check field lengths against packet
>     lengths when unmarshalling packets.
>
>     https://www.samba.org/samba/security/CVE-2026-58224.html
>
> Signed-off-by: Bernd Kuhls <[email protected]>

Applied to 2026.05.x, thanks

_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.