[Pkg-samba-maint] [Git][samba-team/samba][debian/4.23] 63 commits: VERSION: Bump version up to Samba 4.23.9...
Michael Tokarev (@mjt)
gitlab at salsa.debian.org
Tue Jul 28 12:38:52 BST 2026
Michael Tokarev pushed to branch debian/4.23 at Debian Samba Team / samba
Commits:
3e9dfe04 by Stefan Metzmacher at 2026-05-26T14:46:59+02:00
VERSION: Bump version up to Samba 4.23.9...
and re-enable GIT_SNAPSHOT.
Signed-off-by: Stefan Metzmacher <metze at samba.org>
- - - - -
7827b04a by Stefan Metzmacher at 2026-05-28T00:37:12+00:00
s3:smb2_server: failing lease/oplock breaks should call smbd_server_connection_terminate()
If there's a problem sending a lease break we need to
call smbd_server_connection_terminate(xconn).
Currently we only called smbXsrv_connection_disconnect_transport(),
which only closes the low level socket, but it doesn't
cleanup smbXsrv_connection and in case of the last connection
for the smbXsrv_client, so we leave the stale structures and
the stale process behind.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=15995
Signed-off-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Ralph Boehme <slow at samba.org>
(cherry picked from commit 734481e2aa9c9bb20fc9bc8734eba85d2f61be72)
- - - - -
c0607a2f by Stefan Metzmacher at 2026-05-28T00:37:12+00:00
s3:winbindd: let init_dc_connection_rpc() fail if domain->dcname is still NULL
This can happen on a DC itself trying to talk to itself,
which is currently not expected.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=15973
Signed-off-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
(cherry picked from commit 38a9910ac99a015a3dac76b93f02d16e140c05e6)
- - - - -
34c6989c by Stefan Metzmacher at 2026-05-28T00:37:12+00:00
s3:winbindd: replace smbXcli_conn_remote_{name,sockaddr}() with domain->{dcname,dcaddr}
domain->conn.cli might be NULL, so we should not deference it.
init_dc_connection_rpc() already checks that domain->dcname is not
NULL...
BUG: https://bugzilla.samba.org/show_bug.cgi?id=15973
Signed-off-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
(cherry picked from commit 34c4ab4c610960ba587659e077608778970363a0)
- - - - -
38a25047 by Stefan Metzmacher at 2026-05-28T00:37:12+00:00
s3:winbindd: let wb_irpc_SamLogon reject the local domain as RWDC
If the clients use a subdomain of our domain the
'sam' auth backend passed the request along to
the 'winbind' auth backend. If winbindd tries
to use the local domain we hit the case that
an unknown domain was used. So we need to
bounce the request back to 'sam_ignoredomain'.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=15973
Signed-off-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
Autobuild-User(master): Volker Lendecke <vl at samba.org>
Autobuild-Date(master): Tue Apr 28 11:49:16 UTC 2026 on atb-devel-224
(cherry picked from commit b4e612725f9fe11f1791bd170cef8b0dade45ba6)
- - - - -
9d60172b by Shachar Sharon at 2026-05-28T00:37:12+00:00
ctdb-server: Fix use-after-free bug
When 'rev_hdl->fde' is NULL due to failure in tevent_add_fd bail-out
with free-and-error in order to avoid pointer dereferencing 'rev_hdl'
after it is freed.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16068
Signed-off-by: Shachar Sharon <ssharon at redhat.com>
Reviewed-by: Martin Schwenke <martin at meltin.net>
Reviewed-by: Anoop C S <anoopcs at samba.org>
Reviewed-by: Vinit Agnihotri <vagnihot at redhat.com>
Reviewed-by: Avan Thakkar <athakkar at redhat.com>
(cherry picked from commit 88e09693a434d06ab57b14c1c1afe5996422ca0a)
- - - - -
118fd1b4 by Shachar Sharon at 2026-05-28T00:37:12+00:00
ctdb-server: Cleanup child resources via local helper
Define 'revokechild_finish' as resource cleanup helper. Call it either
via destructor (normal case) or upon allocation failure.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16068
Signed-off-by: Shachar Sharon <ssharon at redhat.com>
Reviewed-by: Martin Schwenke <martin at meltin.net>
Reviewed-by: Anoop C S <anoopcs at samba.org>
Reviewed-by: Vinit Agnihotri <vagnihot at redhat.com>
Reviewed-by: Avan Thakkar <athakkar at redhat.com>
Autobuild-User(master): Martin Schwenke <martins at samba.org>
Autobuild-Date(master): Wed May 6 05:28:48 UTC 2026 on atb-devel-224
(cherry picked from commit 67f139ad28c6a771bac488b09d52dda81f3ffe81)
- - - - -
c6d1b346 by Ralph Boehme at 2026-05-28T00:37:12+00:00
smbtorture: rename test smb2.maximum_allowed.read_only to smb2.maximum_allowed.read_only_file
Soon going to add another test for directories called smb2.maximum_allowed.read_only_dir.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16030
Signed-off-by: Ralph Boehme <slow at samba.org>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
(cherry picked from commit 605542e58fb3c436d4a5c0aa5b6b430d135ac7ff)
- - - - -
9b85ed99 by Ralph Boehme at 2026-05-28T00:37:12+00:00
smbtorture: add additional checks to smb2.maximum_allowed.read_only_file
Prooves that:
- the "MxAC" context response actually ignores FILE_ATTRIBUTE_READONLY,
- actuall effective access rights honor FILE_ATTRIBUTE_READONLY (using
RAW_FILEINFO_ACCESS_INFORMATION getinfo level),
- attempting to write to a file with FILE_ATTRIBUTE_READONLY fails.
Test passed against Windows, fails against both s3 and s4 servers. Skipping the
ad_dc_ntvfs test in the future, I'm not going to fix that.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16030
Signed-off-by: Ralph Boehme <slow at samba.org>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
(cherry picked from commit 878e7975de17b5c8218cb2c44b44d8a8fac4f073)
- - - - -
7efa3b5e by Ralph Boehme at 2026-05-28T00:37:12+00:00
smbtorture: add test smb2.maximum_allowed.read_only_dir
Verifies that FILE_ATTRIBUTE_READONLY is effectively ignored on directories.
Passes against Windows, fails against Samba: Samba enforces read-only access in
fsp->access_mask and "MxAC" create context response for directories with
FILE_ATTRIBUTE_READONLY. This is wrong, Windows doesn't do this.
Note that MS-FSA doesn't quite has all these details right, the correct
behaviour was taken from a modern Windows server.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16030
Signed-off-by: Ralph Boehme <slow at samba.org>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
(cherry picked from commit b6d53b25e2788473e3cec483bc6a4220cc9641c1)
- - - - -
7458731a by Ralph Boehme at 2026-05-28T00:37:12+00:00
smbd: split read-only checks in smbd_calculate_maximum_allowed_access_fsp()
Prepares for adjusting the permission when the FILE_ATTRIBUTE_READONLY is set in
the next commmit.
No change in behaviour.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16030
Signed-off-by: Ralph Boehme <slow at samba.org>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
(cherry picked from commit 671c7bb4dc9c7142b7eeaa673b6cc692b5b67425)
- - - - -
e7a8c0e4 by Ralph Boehme at 2026-05-28T00:37:12+00:00
smbd: ignore FILE_ATTRIBUTE_READONLY for the "MxAC" create context
As much as I dislike adding a boolean parameter to control this behaviour, I
don't see a different clean way to do it.
Note that I'm not touching the case where the share is realy-only, I just don't
want to open that additional can of worms now and instead focus on fixing the
FILE_ATTRIBUTE_READONLY case.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16030
Signed-off-by: Ralph Boehme <slow at samba.org>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
(cherry picked from commit 03fa9d035d0bd657eaf46abfd8bedf93681a4338)
- - - - -
3d74e101 by Ralph Boehme at 2026-05-28T00:37:12+00:00
smbd: apply read-only attribute access restrictions only to files
Also mask off the exact access rights given in MS_FSA 2.1.5.1.2.1 "Algorithm to
Check Access to an Existing File".
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16030
Signed-off-by: Ralph Boehme <slow at samba.org>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
(cherry picked from commit 2a1b8321af1755fa424eec8c3931f167a8399127)
- - - - -
3c4c0cff by Ralph Boehme at 2026-05-28T00:37:12+00:00
smbd: do S_ISDIR check even earlier
Doing this in open_file() is too late, as when the client requests an open with
SEC_FLAG_MAXIMUM_ALLOWED on a directory that has FILE_ATTRIBUTE_READ_ONLY set,
this will currently trigger an NT_STATUS_ACCESS_DENIED by the following code in
open_file_ntcreate() if the ACL grants write access to the user:
if (((flags & O_ACCMODE) != O_RDONLY) && file_existed &&
(!CAN_WRITE(conn) ||
(existing_dos_attributes & FILE_ATTRIBUTE_READONLY))) {
DEBUG(5,("open_file_ntcreate: write access requested for "
"file %s on read only %s\n",
smb_fname_str_dbg(smb_fname),
!CAN_WRITE(conn) ? "share" : "file" ));
return NT_STATUS_ACCESS_DENIED;
}
Fixes this bug, but should otherwise cause no change in behaviour.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16030
Signed-off-by: Ralph Boehme <slow at samba.org>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
Autobuild-User(master): Stefan Metzmacher <metze at samba.org>
Autobuild-Date(master): Wed Apr 29 12:00:18 UTC 2026 on atb-devel-224
(cherry picked from commit 4ab12a63a4aa4f3625bc3e81817d0169c9b2766e)
- - - - -
556c7927 by Björn Jacke at 2026-05-28T00:37:12+00:00
samba-tool: fix documentation for timestamp format specifiers
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16076
Signed-off-by: Bjoern Jacke <bjacke at samba.org>
Reviewed-by: Björn Baumbach <bb at sernet.de>
Autobuild-User(master): Björn Jacke <bjacke at samba.org>
Autobuild-Date(master): Tue May 12 11:19:12 UTC 2026 on atb-devel-224
(cherry picked from commit 66fec3d4ff0981456e8548ef8497a5137bbfa755)
- - - - -
f33863d3 by Andreas Schneider at 2026-05-28T01:37:36+00:00
s3:winbind: Do not fallback to NCACN_NP Netlogon/LSA connections for AD domains
BUG: https://bugzilla.samba.org/show_bug.cgi?id=15987
Pair-Programmed-With: Stefan Metzmacher <metze at samba.org>
Signed-off-by: Stefan Metzmacher <metze at samba.org>
Signed-off-by: Andreas Schneider <asn at samba.org>
Reviewed-by: Pavel Filipenský <pfilipensky at samba.org>
Autobuild-User(master): Pavel Filipensky <pfilipensky at samba.org>
Autobuild-Date(master): Mon May 11 21:24:02 UTC 2026 on atb-devel-224
(cherry picked from commit 33628fd9da56afc0fa1a480b7df2f73e4e0d3664)
Autobuild-User(v4-23-test): Björn Jacke <bjacke at samba.org>
Autobuild-Date(v4-23-test): Thu May 28 01:37:36 UTC 2026 on atb-devel-224
- - - - -
8c76f92d by Volker Lendecke at 2026-06-08T16:54:19+00:00
libsecurity: Fix security_acl_dup()'s talloc hierarchy
With claims and conditions, ACEs are no longer simple blobs, they
themselves are structures with talloc children. This means
talloc_memdup() is no longer sufficient to copy an ACE. Copy the whole
ACL via NDR.
Bug: https://bugzilla.samba.org/show_bug.cgi?id=16095
Signed-off-by: Volker Lendecke <vl at samba.org>
Reviewed-by: Noel Power <noel.power at suse.com>
Autobuild-User(master): Volker Lendecke <vl at samba.org>
Autobuild-Date(master): Mon Jun 8 11:47:54 UTC 2026 on atb-devel-224
(cherry picked from commit c137ec34c4aebf889943677f6426583029eb4cd4)
- - - - -
0129c019 by Gary Lockyer at 2026-06-08T16:54:19+00:00
lib:util add pointer overflow checks
The wrapping of pointer arithmetic is undefined behaviour. Clang from version
20 onwards will treat checks like:
ptr + offset < ptr
As always evaluating to true.
This commit adds the macros:
offset_outside_range
ptr_overflow
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16092
Signed-off-by: Gary Lockyer <gary at catalyst.net.nz>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
(Backported from commit 2e53f7196f45d28689f25a57fa84995eceee4585)
test_json_logging not present in v23
- - - - -
9bed3dc2 by Gary Lockyer at 2026-06-08T16:54:19+00:00
s3:libsmb:clilist fix tautological-compare
The wrapping of pointer arithmetic is undefined behaviour. Clang from version 20
onwards will treat an overflow check of the following form:
ptr + offset < ptr
as always evaluating to false.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16092
Signed-off-by: Gary Lockyer <gary at catalyst.net.nz>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
- - - - -
4ff95725 by Gary Lockyer at 2026-06-08T16:54:19+00:00
libcli:auth:msrpc_parse fix white space
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16092
Signed-off-by: Gary Lockyer <gary at catalyst.net.nz>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
- - - - -
3d115fd1 by Gary Lockyer at 2026-06-08T16:54:19+00:00
libcli:auth:msrpc_parse fix tautological-compare
The wrapping of pointer arithmetic is undefined behaviour. Clang from version 20
onwards will treat an overflow check of the following form:
ptr + offset < ptr
as always evaluating to false
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16092
Signed-off-by: Gary Lockyer <gary at catalyst.net.nz>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
(cherry picked from commit d80c9dac0765a5b114718450ec5a062cd2b6f86f)
- - - - -
da619c48 by Gary Lockyer at 2026-06-08T16:54:19+00:00
s3/torture/test_smb1_dfs fix tautological-compare
The wrapping of pointer arithmetic is undefined behaviour. Clang from version 20
onwards will treat an overflow check of the following form:
ptr + offset < ptr
as always evaluating to false.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16092
Signed-off-by: Gary Lockyer <gary at catalyst.net.nz>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
(cherry picked from commit 769cf0a0ddb5c7af65afa5b764c24a3416025745)
- - - - -
2f0fe8c2 by Gary Lockyer at 2026-06-08T16:54:19+00:00
s3:utils:clirap2 fix tautological-compare
The wrapping of pointer arithmetic is undefined behaviour. Clang from version 20
onwards will treat an overflow check of the following form:
ptr + offset < ptr
as always evaluating to false
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16092
Signed-off-by: Gary Lockyer <gary at catalyst.net.nz>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
(cherry picked from commit 3287641bbf3360c8241db090781ebc2d5febbc96)
- - - - -
f3bef4a8 by Gary Lockyer at 2026-06-08T16:54:19+00:00
s3:libsmb:cliquota fix tautological-compare
The wrapping of pointer arithmetic is undefined behaviour. Clang from version 20
onwards will treat an overflow check of the following form:
ptr + offset < ptr
as always evaluating to false
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16092
Signed-off-by: Gary Lockyer <gary at catalyst.net.nz>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
(cherry picked from commit b58d7045d5444d70db58d07d7746006ea1b9ecfb)
- - - - -
0d0a2097 by Gary Lockyer at 2026-06-08T16:54:19+00:00
build: enable tautological-compare errors
Now that all the warnings have been removed, and as they did in fact reveal
real issues lets make it an error.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16092
Signed-off-by: Gary Lockyer <gary at catalyst.net.nz>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
(cherry picked from commit 3485f58ea1c2a4013b0ab60c1ddee0faa4eb3eea)
- - - - -
b1443f70 by Stefan Metzmacher at 2026-06-08T16:54:19+00:00
build: add -Werror=tautological-compare
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16092
Signed-off-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
(Backported from commit fb188140357a5d8796c47c5fd88c8a25117bda8e)
-Werror=array-bounds and -Werror=stringop-overlow
- - - - -
16d92be9 by Stefan Metzmacher at 2026-06-08T18:07:49+00:00
s3:winbindd: ignore unsupported anonymous smb sessions for AD trusts
This is handles the cases where a DC has
'Require NTLMv2 session security' activated which
disables anonymous NTLMSSP and let the server return
NT_STATUS_NOT_SUPPORTED.
Similar problems happen with a Samba DC that
uses 'restrict anonymous = 2' and the
tcon to ipc$ fails with NT_STATUS_ACCESS_DENIED.
For active directory related trusts we only use
ncacn_ip_tcp (or ncalrpc), so there's no need for
a valid smb connection.
Historically it very hard to restructure the code
in order to only connect smb for ncacn_np, so
this is more a hack to let us work in real world
scenarios.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14638
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16067
Signed-off-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Bjoern Jacke <bjacke at samba.org>
(cherry picked from commit c63880a1ec3e930dca1a511f4610a94483418e01)
Autobuild-User(v4-23-test): Björn Jacke <bjacke at samba.org>
Autobuild-Date(v4-23-test): Mon Jun 8 18:07:49 UTC 2026 on atb-devel-224
- - - - -
859038dd by Andreas Schneider at 2026-06-23T08:44:13+00:00
s3:tests: Improve debugging for test_wbinfo_lookuprids_cache.sh
Note that if this test fails, it is like something else creating keys.
The last time it was a crashing smbd which left a key in the database
and this test failed as a result.
BUG: https://bugzilla.samba.org/attachment.cgi?bugid=16011
Signed-off-by: Andreas Schneider <asn at samba.org>
Reviewed-by: Guenther Deschner <gd at samba.org>
Autobuild-User(master): Günther Deschner <gd at samba.org>
Autobuild-Date(master): Wed Apr 22 16:35:58 UTC 2026 on atb-devel-224
(cherry picked from commit c24438ca972c98db533400d1afebc02fdc29bba6)
- - - - -
08090942 by Volker Lendecke at 2026-06-23T08:44:13+00:00
tests: Fix some wbinfo_lookuprids_cache flakyness
If the key contains spaces, the shell qouting through "testit" does
not work properly. Avoid having to fix that quoting by replacing
spaces with '\20'.
You can force it by setting the
my $samsid = "S-1-5-21-1-32-" . int(rand(4294967295));
in selftest/target/Samba3.pm.
BUG: https://bugzilla.samba.org/attachment.cgi?bugid=16011
Signed-off-by: Volker Lendecke <vl at samba.org>
Reviewed-by: Guenther Deschner <gd at samba.org>
Autobuild-User(master): Günther Deschner <gd at samba.org>
Autobuild-Date(master): Mon Jun 8 14:49:01 UTC 2026 on atb-devel-224
(cherry picked from commit 27f57d26f950c6fbe62f9b8ef8bd5fb503f587e5)
- - - - -
a5f7550a by Volker Lendecke at 2026-06-23T08:44:13+00:00
tests: Fix samba4.blackbox.net_ads_join flakyness
We have to leave against the same DC that we joined against, the
replication cycle might not have kicked in.
Normally, the server affinity cache takes care of this, but in this
test it's disabled.
Signed-off-by: Volker Lendecke <vl at samba.org>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
(cherry picked from commit f5d858005a064a23321e78f68372eb1f8841fdc3)
- - - - -
332434df by Günther Deschner at 2026-06-23T08:44:13+00:00
s4-torture: add test for FILE_NOTIFY_CHANGE_SECURITY
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14148
Guenther
Signed-off-by: Guenther Deschner <gd at samba.org>
Reviewed-by: Jeremy Allison <jra at samba.org>
(cherry picked from commit 29e51f3ed935d0475b1715f82560ee356ab5e401)
- - - - -
97ad39f8 by Günther Deschner at 2026-06-23T09:52:39+00:00
s3-smbd: send notifications for ACL changes
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14148
Guenther
Signed-off-by: Guenther Deschner <gd at samba.org>
Reviewed-by: Jeremy Allison <jra at samba.org>
Autobuild-User(master): Jeremy Allison <jra at samba.org>
Autobuild-Date(master): Thu Nov 6 02:42:06 UTC 2025 on atb-devel-224
(cherry picked from commit 2be7c0c2f927042843fb8a2ea0b9c67d1f969d00)
Autobuild-User(v4-23-test): Björn Jacke <bjacke at samba.org>
Autobuild-Date(v4-23-test): Tue Jun 23 09:52:39 UTC 2026 on atb-devel-224
- - - - -
6066bd2f by Björn Jacke at 2026-06-23T12:03:11+02:00
WHATSNEW: Add release notes for Samba 4.23.9.
Signed-off-by: Bjoern Jacke <bjacke at samba.org>
- - - - -
360b66d5 by Björn Jacke at 2026-06-23T12:03:59+02:00
VERSION: Disable GIT_SNAPSHOT for the 4.23.9 release.
Signed-off-by: Bjoern Jacke <bjacke at samba.org>
- - - - -
6a628e79 by Björn Jacke at 2026-06-23T12:04:59+02:00
VERSION: Bump version up to Samba 4.23.10...
and re-enable GIT_SNAPSHOT.
Signed-off-by: Bjoern Jacke <bjacke at samba.org>
- - - - -
d2ef0ce0 by Stefan Metzmacher at 2026-07-20T17:20:30+02:00
CVE-2026-6949: ndr_dns: let ndr_pull_dns_res_rec() remember the start offset
In order to verify TSIG signatures we need a reliable way to
truncate the original dns_name_packet buffer before the
last additional dns_res_rec.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16083
Signed-off-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Douglas Bagnall <dbagnall at samba.org>
- - - - -
20798d41 by Stefan Metzmacher at 2026-07-20T17:20:30+02:00
CVE-2026-6949: s4:dns_server: correctly truncate the buffer for TSIG verification
Calculating the length of the TSIG additional dns_res_rec,
via ndr_push_dns_res_rec() is fragile and may generate
a buffer larger than the original dns_name_packet buffer.
This could underflow the resulting packet_len,
to a very large value and buffer_len to a small value.
Resulting in a memcpy() of a very large size into
a very small buffer. This most likely already
gets a segmentation fault when reading after the
in->data.
This was reported by Arjun Basnet with Securin Labs.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16083
Signed-off-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Douglas Bagnall <dbagnall at samba.org>
- - - - -
8c979746 by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-daemon: Avoid out of bounds data access
Protocol field lengths need to be validated to avoid attempts to
access memory beyond the end of the packet buffer.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Reported-by: Tristan Madani <tristan at talencesecurity.com>
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
94e1cec5 by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-protocol: Avoid DoS memory allocation
The pull loop already avoids out of bounds accesses beyond the end of
the buffer. However, it does not avoid a DoS memory allocation due to
an unreasonably large array size.
Check that the number of specified array elements can be pulled from
buffer, which puts a reasonable upper bound on the subsequent memory
allocation.
Use an initialised dummy variable to avoid static analysers
complaining about uninitialised variables being passed. Variable i
could be reused but that might be confusing, so leave any optimisation
to the compiler.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Reported-by: Martin Schwenke <mschwenke at ddn.com>
Reported-by: Also Andrew Tridgell (issue 22)
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
b41a631f by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-daemon: Avoid out-of-bounds data access
Do not allow the VNN map's size to extend past the end of the buffer.
This is checked by switching to ctdb_vnn_map_pull(), which also
simplifies the code.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
de7ab1fd by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-daemon: Avoid out of bounds data access
If a NUL terminator doesn't appear in the buffer then the database
name is not a valid string.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
9c060670 by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-daemon: Avoid out of bounds data access
The count can't exceed the recdata buffer size.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
293fe0c9 by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-daemon: Avoid out of bounds data access
The count can't exceed the indata buffer size.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
d686b157 by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-daemon: Avoid out of bounds data access
The first check is clearly needed because m->db_id is referenced. The
second check is handled by a similar update to
ctdb_control_update_record(), but repeat it in case something else
changes.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
a1256fcd by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-daemon: Avoid out of bounds data access
Instead of checking only that there is enough data for the length
field, check there is enough data for the entire header part of the
struct. After cross-checking overall lengths, ensure there is enough
data for the key/data in the data element.
While here, modernise the DEBUG.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Reported-by: Andrew Tridgell (issue 13)
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
843557f3 by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-protocol: Avoid off-by-one error for bytes pulled
As per the comment, if there is no NUL byte in the buffer then don't
count one in the number of bytes pulled.
Note that this is unlikely to be a security issue because it would
take a protocol bug elsewhere to overrun the buffer. However, include
this fix here for posterity.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Reported-by: Andrew Tridgell (issue 16)
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
467e96bf by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-protocol: Always pull the specified number of bytes
The string should not contain a premature NUL terminator, which would
cause less than the specified number of bytes to be pulled. If it
does, consume the specified number of bytes anyway. The alternative
doesn't make sense.
Note that this is unlikely to be a security issue, where trailing data
in the string field causes the buffer to be overrun. That would
require an additional protocol bug. However, include this fix here
for posterity.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
1e3c4a6b by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-protocol: Avoid DoS memory allocations
The pull loop already avoids out of bounds accesses beyond the end of
the buffer. However, it does not avoid a DoS memory allocation due to
an unreasonably large array size.
Check that the number of specified array elements can be pulled from
buffer, which puts a reasonable upper bound on the subsequent memory
allocation.
Use an initialised dummy variable to avoid static analysers
complaining about uninitialised variables being passed.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Reported-by: Andrew Tridgell (issue 22)
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
c056fcb0 by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-protocol: Avoid DoS memory allocations
The pull loop already avoids out of bounds accesses beyond the end of
the buffer. However, it does not avoid a DoS memory allocation due to
an unreasonably large array size.
Check that the number of specified array elements can be pulled from
buffer, which puts a reasonable upper bound on the subsequent memory
allocation.
Use an initialised dummy variable to avoid static analysers
complaining about uninitialised variables being passed.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
d6950d42 by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-common: Secure sock_daemon Unix domain sockets
Currently, the mode of the socket depends on the creating process's
umask. This might allow unwanted access.
It might be preferable to do this just for the eventd socket.
However, there is no useful place to hook this in outside of
sock_daemon.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
7f053069 by Martin Schwenke at 2026-07-20T17:20:30+02:00
CVE-2026-58224: ctdb-doc: Emphasise that the private network must be private
Note that the difference in the first couple of lines is leading
whitespace being switch to a TAB.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Tristan Madani <tristan at talencesecurity.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
85b6714b by Martin Schwenke at 2026-07-20T17:20:31+02:00
CVE-2026-58224: ctdb-common: Add comments to ward off vulnerability reports
We can't deal with this in the current CTDB protocol without
disproportionate effort. So, document reality clearly in the code to
try to stop these from being reported.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16085
Signed-off-by: Martin Schwenke <mschwenke at ddn.com>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
4fb7188b by Douglas Bagnall at 2026-07-20T17:20:31+02:00
CVE-2026-58216: kdc:kpasswd: calculate correct size for password blob
We were making the enc_data_blob 6 bytes too big.
Its payload is an ASN.1 structure that knows its own size, so the
extra bytes are not usually read by Heimdal, but a crafted packet
could force them to be read.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16087
Reported-by: Tristan <TristanInSec at gmail.com>
Signed-off-by: Douglas Bagnall <douglas.bagnall at catalyst.net.nz>
Reviewed-by: Stefan Metzmacher <metze at samba.org>
- - - - -
51a7e073 by Volker Lendecke at 2026-07-20T17:20:31+02:00
CVE-2026-58218: dns_server: Fix an error path memleak
We talloc the new key off "dns->tkeys", which is long-lived. On any
error we never free'd that again. Probably not remotely triggerable,
this is only setting up the gensec context.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16115
Signed-off-by: Volker Lendecke <vl at samba.org>
Reviewed-by: Douglas Bagnall <dbagnall at samba.org>
- - - - -
9f9981bf by Volker Lendecke at 2026-07-20T17:20:31+02:00
CVE-2026-58218: dns_server: Only add a tkey after successful authentication
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16115
Signed-off-by: Volker Lendecke <vl at samba.org>
Reviewed-by: Douglas Bagnall <dbagnall at samba.org>
- - - - -
a0081c81 by Stefan Metzmacher at 2026-07-20T17:20:31+02:00
CVE-2026-58221: s4:dsdb: provide dsdb_audit_{log_attributes,operation_human_readable}() functions
They are useful outside of audit_log.c soon.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16147
Signed-off-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
Reviewed-by: Douglas Bagnall <douglas.bagnall at catalyst.net.nz>
[backport: modified for v4.22, not removing the static versions used
in audit_log.c or adjusting the tests]
- - - - -
f0880127 by Stefan Metzmacher at 2026-07-20T17:20:31+02:00
CVE-2026-58221: s4:dsdb: let rootdse_filter_operations() reject untrusted operations on special DNs
Without this authenticated (also non-admin) users write internal meta
data leading to admin privileges.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16147
Signed-off-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>
Reviewed-by: Douglas Bagnall <douglas.bagnall at catalyst.net.nz>
- - - - -
3ba20d57 by Stefan Metzmacher at 2026-07-21T17:02:52+02:00
CVE-2026-58222: s4:ldap_server: don't allow untrusted compare requests for confidential attributes
This means we apply acl checks against the search filter similar
to normal ldb searches.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16148
Signed-off-by: Stefan Metzmacher <metze at samba.org>
Reviewed-by: Douglas Bagnall <douglas.bagnall at catalyst.net.nz>
- - - - -
511485c9 by Björn Jacke at 2026-07-21T17:02:58+02:00
WHATSNEW: Add release notes for Samba 4.23.10.
Signed-off-by: Bjoern Jacke <bjacke at samba.org>
Signed-off-by: Stefan Metzmacher <metze at samba.org>
- - - - -
2f21145f by Björn Jacke at 2026-07-21T17:02:58+02:00
VERSION: Disable GIT_SNAPSHOT for the 4.23.10 release.
Signed-off-by: Bjoern Jacke <bjacke at samba.org>
Signed-off-by: Stefan Metzmacher <metze at samba.org>
- - - - -
02de68fd by Michael Tokarev at 2026-07-28T14:19:48+03:00
New upstream version 4.23.10+dfsg
- - - - -
9a6803c1 by Michael Tokarev at 2026-07-28T14:20:14+03:00
Update upstream source from tag 'upstream/4.23.10+dfsg'
Update to upstream version '4.23.10+dfsg'
with Debian dir f3198be52cd32cf41ce6cc7bf754b1dcee7fbe43
- - - - -
a3ed2a9d by Michael Tokarev at 2026-07-28T14:37:39+03:00
update changelog; upload version 4.23.10+dfsg-1 to unstable
- - - - -
53 changed files:
- VERSION
- WHATSNEW.txt
- buildtools/wafsamba/samba_autoconf.py
- ctdb/common/ctdb_io.c
- ctdb/common/pkt_read.c
- ctdb/common/sock_daemon.c
- ctdb/doc/ctdb.7.xml
- ctdb/protocol/protocol_basic.c
- ctdb/protocol/protocol_types.c
- ctdb/server/ctdb_call.c
- ctdb/server/ctdb_client.c
- ctdb/server/ctdb_control.c
- ctdb/server/ctdb_ltdb_server.c
- ctdb/server/ctdb_persistent.c
- ctdb/server/ctdb_recover.c
- ctdb/server/ctdb_traverse.c
- ctdb/server/ctdb_update_record.c
- debian/changelog
- + lib/util/overflow.h
- + lib/util/tests/test_overflow.c
- lib/util/wscript_build
- libcli/auth/msrpc_parse.c
- libcli/security/security_descriptor.c
- librpc/idl/dns.idl
- librpc/ndr/ndr_dns.c
- python/samba/netcmd/user/readpasswords/show.py
- source3/libsmb/clilist.c
- source3/libsmb/cliquota.c
- source3/modules/vfs_fruit.c
- source3/script/tests/test_wbinfo_lookuprids_cache.sh
- source3/smbd/fake_file.c
- source3/smbd/globals.h
- source3/smbd/open.c
- source3/smbd/smb2_create.c
- source3/smbd/smb2_nttrans.c
- source3/smbd/smb2_server.c
- source3/torture/test_smb1_dfs.c
- source3/utils/clirap2.c
- source3/winbindd/winbindd.h
- source3/winbindd/winbindd_cm.c
- source3/winbindd/winbindd_irpc.c
- source4/dns_server/dns_crypto.c
- source4/dns_server/dns_query.c
- source4/dsdb/samdb/ldb_modules/audit_util.c
- source4/dsdb/samdb/ldb_modules/rootdse.c
- source4/dsdb/samdb/ldb_modules/wscript_build_server
- source4/kdc/kpasswd-service.c
- source4/ldap_server/ldap_backend.c
- source4/librpc/tests/dns-decode_dns_name_packet-hex.txt
- source4/selftest/tests.py
- source4/torture/smb2/max_allowed.c
- source4/torture/smb2/notify.c
- testprogs/blackbox/test_net_ads_join_to_preferred_dc.sh
The diff was not included because it is too large.
View it on GitLab: https://salsa.debian.org/samba-team/samba/-/compare/4487a3865f3af4c310833b3ef7838530e3dcf920...a3ed2a9d043dc2777f26cb2f8014a64a4ac6aaa2
--
View it on GitLab: https://salsa.debian.org/samba-team/samba/-/compare/4487a3865f3af4c310833b3ef7838530e3dcf920...a3ed2a9d043dc2777f26cb2f8014a64a4ac6aaa2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/pkg-samba-maint/attachments/20260728/6f0e381f/attachment-0001.htm>
More information about the Pkg-samba-maint
mailing list