Opened 6 months ago

Closed 3 months ago

#23163 closed enhancement (fixed)

samba-4.24.3

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (8)

comment:1 by Douglas R. Reno, 5 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:2 by Douglas R. Reno, 5 months ago

Priority: normal → high

Now 4.24.2, which includes a CVE fix for the bundled ngtcp2 library

Changes since 4.24.1
--------------------

o  Vinit Agnihotri <vagnihot@redhat.com>
   * BUG 16038: Samba 4.24 with cups can't get queue and shows errors about
     fetch_share_cache_time

o  Thales Antunes de Oliveira Barretto <thales.barretto.git@gmail.com>
   * BUG 16043: Fix a directory file descriptor leak in vfs_glusterfs that
     caused      unbounded memory growth on the GlusterFS brick with
     persistent SMB2      connections.

o  Ralph Boehme <slow@samba.org>
   * BUG 16030: Windows Offline Files fails with permission error when directory
     has the read‑only attribute set

o  Pavel Filipenský <pfilipensky@samba.org>
   * BUG 15991: samba not triggering mount of zfs snapshot in dataset
     .zfs/snapshots/<snapname> directory
   * BUG 15999: net ads join still fails with multiple DCs

o  Björn Jacke <bjacke@samba.org>
   * BUG 16076: samba-tool shows wrong format specifiers for timestamp
     attributes

o  Stefan Metzmacher <metze@samba.org>
   * BUG 14638: restrict anonymous = 2 breaks RODC functionality
   * BUG 15973: smbpasswd can crash winbindd on an AD DC
   * BUG 15995: smbd does not cleanup on disconnect of the transport connection
     on lease break errors
   * BUG 16059: CVE-2026-40170: thirdparty ngtcp2 needs to be updated
   * BUG 16067: Require NTLMv2 session security on Windows makes trusts to Samba
     unusable
   * BUG 16073: Winbind can change Ownership Of / To A User Who has Homedir / In
     passwd

o  Andreas Schneider <asn@samba.org>
   * BUG 15987: Winbind lsa_OpenPolicy() fails on lsa connection setup with:
     NT_STATUS_RPC_CANNOT_SUPPORT

o  Shachar Sharon <ssharon@redhat.com>
   * BUG 16068: CTDB read-only record handling contains use after free and
     resource leak bugs

comment:3 by Douglas R. Reno, 5 months ago

Summary: samba-4.24.1 → samba-4.24.3

Now 4.24.3.

Release Announcements
---------------------

This is a security release in order to address the following defects:

o CVE-2026-1933:   Missing access checks on reparse point operations

                   On a share marked "read only = yes" and
                   on file handles opened R/O users can set
                   or delete the reparse point xattrs on files
                   that the user has write-access in the file
                   system for.

                   https://www.samba.org/samba/security/CVE-2026-1933.html


o CVE-2026-2340:   WORM vfs module does not block overwrites

                   The WORM (Write-Once, Read Many) vfs module
                   is supposed to lock write access to shared
                   files, so they cannot be altered after initial
                   writes. It was allowing files to be overwritten
                   by renaming a newly created file over a protected
                   file.

                   https://www.samba.org/samba/security/CVE-2026-2340.html


o CVE-2026-3012:   auto-enrolment GPO installing CA certificate over http
                   without verification

                   To bootstrap a certificate chain a domain member must
                   fetch a certificate without TLS. It was trusting HTTP
                   for this when a more secure encrypted LDAP channel
                   was also available.

                   https://www.samba.org/samba/security/CVE-2026-3012.html


o CVE-2026-3238:   Denial of service against AD DC WINS server

                   The WINS server component of the Active
                   Directory Domain controller code in Samba
                   is vulnerable to a NULL pointer dereference
                   and crash caused by a unauthenticated UDP
                   packet.

                   https://www.samba.org/samba/security/CVE-2026-3238.html


o CVE-2026-4408:   Unauthenticated Remote Code Execution in Samba DCE/RPC SAMR
                   server

                   Samba file servers and classic (non-AD) domain controllers
                   with samba-dcerpcd started as a system service and with a
                   "check password script" that has the %u substitution
                   character are vulnerable to a remote code execution.

                   https://www.samba.org/samba/security/CVE-2026-4408.html


o CVE-2026-4480:   Unauthenticated Remote Code Execution in Samba printing
                   subsystem

                   Samba print servers with a "print command"
                   that has the %J substitution character
                   are vulnerable to a Remote Code Execution.

                   https://www.samba.org/samba/security/CVE-2026-4480.html


Changes
-------

o  Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
   * BUG 15997: CVE-2026-2340
   * BUG 16003: CVE-2026-3012
   * BUG 16033: CVE-2026-4480
   * BUG 16034: CVE-2026-4408

o  Pavel Kohout <pavel@aisle.com>
   * BUG 15997: CVE-2026-2340

o  Volker Lendecke <vl@samba.org>
   * BUG 15992: CVE-2026-1933
   * BUG 16012: CVE-2026-3238

o  Stefan Metzmacher <metze@samba.org>
   * BUG 15992: CVE-2026-1933
   * BUG 16033: CVE-2026-4480
   * BUG 16034: CVE-2026-4408
   * BUG 16059: (4.23-only) CVE-2026-40170: thirdparty ngtcp2 needs to be updated
   * BUG 16073: (4.22/23-only) Winbind can change Ownership Of / To A User Who
     has Homedir / In passwd

comment:4 by Douglas R. Reno, 4 months ago

Owner: changed from Douglas R. Reno to blfs-book
Status: assigned → new

I'm going to reassign these to the book for now so whoever wants to do them can do them.

In the meantime I will continue working on rivendell, but I do not want to continue holding the project back on important issues.

comment:5 by Douglas R. Reno, 4 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:6 by Douglas R. Reno, 4 months ago

Owner: changed from Douglas R. Reno to SecurityAdvisory
Status: assigned → new

Fixed at b562b848e312a6a97cf3b8869de5e9b80ea3cf6a

Reassigning to SecurityAdvisory for an advisory to be filed

comment:7 by Bruce Dubbs, 3 months ago

Milestone: 13.1 → 98-Security

comment:8 by Bruce Dubbs, 3 months ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-132 issued.

Note: See TracTickets for help on using tickets.