[ubuntu/plucky-security] samba 2:4.21.4+dfsg-1ubuntu3.5 (Accepted)

Eduardo Barretto eduardo.barretto at canonical.com
Thu Oct 16 07:15:10 UTC 2025


samba (2:4.21.4+dfsg-1ubuntu3.5) plucky-security; urgency=medium

  * SECURITY UPDATE: uninitialized memory disclosure via vfs_streams_xattr
    - debian/patches/CVE-2025-9640-1.patch: add torture test for inserting
      hole in stream in source3/selftest/tests.py, source4/torture/*.
    - debian/patches/CVE-2025-9640-2.patch: fix unitialized write in
      source3/modules/vfs_streams_xattr.c.
    - CVE-2025-9640
  * SECURITY UPDATE: command injection via WINS server hook script
    - debian/patches/CVE-2025-10230-1.patch: check that wins hook sanitizes
      names in python/samba/tests/usage.py, selftest/*, source4/torture/*,
      testprogs/blackbox/wins_hook_test.
    - debian/patches/CVE-2025-10230-2.patch: restrict names fed to shell in
      source4/nbt_server/wins/wins_hook.c.
    - CVE-2025-10230

samba (2:4.21.4+dfsg-1ubuntu3.4) plucky; urgency=medium

  * Upcoming changes to Windows Server enforce security checks even on
    schannel secured NETLOGON connections causing winbind's netlogon dc
    discovery calls to fail. (LP: #2116098):
    - d/p/s3-winbindd-avoid-using-any-netlogon-call-to-get-a-d.patch: avoid
      using any netlogon call to get a dc name
    - d/p/s3-winbindd-Fix-internal-winbind-dsgetdcname-calls-w.patch: Fix
      internal winbind dsgetdcname calls w.r.t. domain name

samba (2:4.21.4+dfsg-1ubuntu3.3) plucky; urgency=medium

  * d/p/fix-18548.patch: fix crash around lack of lock checking (LP: #2108981)

samba (2:4.21.4+dfsg-1ubuntu3.2) plucky; urgency=medium

  * Fix updating an existing MOTD GPO (LP: #2107395):
    - d/p/fix-update-motd-gpo.patch: replace with upstream's version which
      includes another fix for the case of updating an existing MOTD GPO
    - d/t/samba-ad-dc-provisioning-internal-dns: add MOTD GPO test
    - d/p/fix-motd-gpo-list-empty.patch: fix crash when listing an empty MOTD
      GPO

Date: 2025-10-10 12:02:19.435930+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Eduardo Barretto <eduardo.barretto at canonical.com>
https://launchpad.net/ubuntu/+source/samba/2:4.21.4+dfsg-1ubuntu3.5
-------------- next part --------------
Sorry, changesfile not available.


More information about the plucky-changes mailing list