[Pkg-samba-maint] [Git][samba-team/samba][debian/4.22] 3 commits: d/patches: bug-16018-v4-22-06.patch, the May-2026 security bugfix (combined)
Michael Tokarev (@mjt)
gitlab at salsa.debian.org
Mon Jul 20 15:24:21 BST 2026
Michael Tokarev pushed to branch debian/4.22 at Debian Samba Team / samba
Commits:
8b74d343 by Michael Tokarev at 2026-05-15T06:38:20+03:00
d/patches: bug-16018-v4-22-06.patch, the May-2026 security bugfix (combined)
- - - - -
474ef199 by Michael Tokarev at 2026-05-15T06:40:36+03:00
update changelog; upload version 4.22.8+dfsg-0+deb13u2 to trixie-security
- - - - -
8fda7936 by Michael Tokarev at 2026-06-11T07:34:29+03:00
Merge branch 'debian/trixie' into debian/4.22
Merge trixie branch and 4.22 branch, switch to the upstream code
- - - - -
1 changed file:
- debian/changelog
Changes:
=====================================
debian/changelog
=====================================
@@ -1,57 +1,47 @@
-samba (2:4.22.10+dfsg-0) unstable; urgency=medium
+samba (2:4.22.10+dfsg-0+deb13u1) trixie; urgency=medium
+
+ * switch to actual upstream release for the May-2026 security fixes:
* This is a security release in order to address the following defects:
CVE-2026-1933: Missing access checks on reparse point operations
-
On a share marked "read only = yes" and on file handles opened R/O users
can set or delete the reparse point xattrs on files that the user has
write-access in the file system for.
-
https://www.samba.org/samba/security/CVE-2026-1933.html
CVE-2026-2340: WORM vfs module does not block overwrites
-
The WORM (Write-Once, Read Many) vfs module is supposed to lock write
access to shared files, so they cannot be altered after initial writes.
It was allowing files to be overwritten by renaming a newly created file
over a protected file.
-
https://www.samba.org/samba/security/CVE-2026-2340.html
CVE-2026-3012: auto-enrolment GPO installing CA certificate over http
without verification
-
To bootstrap a certificate chain a domain member must fetch a certificate
without TLS. It was trusting HTTP for this when a more secure encrypted
LDAP channel was also available.
-
https://www.samba.org/samba/security/CVE-2026-3012.html
CVE-2026-3238: Denial of service against AD DC WINS server
-
The WINS server component of the Active Directory Domain controller code
in Samba is vulnerable to a NULL pointer dereference and crash caused by
an unauthenticated UDP packet.
-
https://www.samba.org/samba/security/CVE-2026-3238.html
CVE-2026-4408: Unauthenticated Remote Code Execution in Samba DCE/RPC
SAMR server
-
Samba file servers and classic (non-AD) domain controllers with
samba-dcerpcd started as a system service and with a "check password
script" that has the %u substitution character are vulnerable to a
remote code execution.
-
https://www.samba.org/samba/security/CVE-2026-4408.html
CVE-2026-4480: Unauthenticated Remote Code Execution in Samba
printing subsystem
-
Samba print servers with a "print command" that has the %J substitution
character are vulnerable to a Remote Code Execution.
-
https://www.samba.org/samba/security/CVE-2026-4480.html
-- Michael Tokarev <mjt at tls.msk.ru> Tue, 26 May 2026 15:46:55 +0300
@@ -75,6 +65,27 @@ samba (2:4.22.9+dfsg-0+deb13u1) trixie; urgency=medium
-- Michael Tokarev <mjt at tls.msk.ru> Fri, 10 Apr 2026 20:21:47 +0300
+samba (2:4.22.8+dfsg-0+deb13u2) trixie-security; urgency=medium
+
+ * https://bugzilla.samba.org/show_bug.cgi?id=16018
+ May-2026 samba security update fixing the following issues:
+ CVE-2026-1933: Missing access check on reparse point operations
+ https://bugzilla.samba.org/show_bug.cgi?id=15992
+ CVE-2026-2340: vfs_worm does not block directory modification
+ https://bugzilla.samba.org/show_bug.cgi?id=15997
+ CVE-2026-3012: group policy certificate enrollment uses http://
+ without validation
+ https://bugzilla.samba.org/show_bug.cgi?id=16003
+ CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server
+ https://bugzilla.samba.org/show_bug.cgi?id=16012
+ CVE-2026-4480: Unauthenticated Remote Code Execution using print command
+ https://bugzilla.samba.org/show_bug.cgi?id=16033
+ CVE-2026-4408: Remote Code Execution in SAMR when check password script
+ contains %u substitution placeholder
+ https://bugzilla.samba.org/show_bug.cgi?id=16034
+
+ -- Michael Tokarev <mjt at tls.msk.ru> Fri, 15 May 2026 06:38:23 +0300
+
samba (2:4.22.8+dfsg-0+deb13u1) trixie; urgency=medium
* new upstream stable/bugfix release:
View it on GitLab: https://salsa.debian.org/samba-team/samba/-/compare/1d4397c31639edf4f4355bb8cbce3032d8328016...8fda7936460ea4b0121e4b4f4f3e45ae20a0bf57
--
View it on GitLab: https://salsa.debian.org/samba-team/samba/-/compare/1d4397c31639edf4f4355bb8cbce3032d8328016...8fda7936460ea4b0121e4b4f4f3e45ae20a0bf57
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/pkg-samba-maint/attachments/20260720/17abf68d/attachment-0001.htm>
More information about the Pkg-samba-maint
mailing list