Opened 6 months ago
Closed 3 months ago
#23163 closed enhancement (fixed)
samba-4.24.3
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (8)
comment:1 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 5 months ago
| Priority: | normal → high |
|---|
comment:3 by , 5 months ago
| Summary: | samba-4.24.1 → samba-4.24.3 |
|---|
Now 4.24.3.
Release Announcements
---------------------
This is a security release in order to address the following defects:
o CVE-2026-1933: Missing access checks on reparse point operations
On a share marked "read only = yes" and
on file handles opened R/O users can set
or delete the reparse point xattrs on files
that the user has write-access in the file
system for.
https://www.samba.org/samba/security/CVE-2026-1933.html
o CVE-2026-2340: WORM vfs module does not block overwrites
The WORM (Write-Once, Read Many) vfs module
is supposed to lock write access to shared
files, so they cannot be altered after initial
writes. It was allowing files to be overwritten
by renaming a newly created file over a protected
file.
https://www.samba.org/samba/security/CVE-2026-2340.html
o CVE-2026-3012: auto-enrolment GPO installing CA certificate over http
without verification
To bootstrap a certificate chain a domain member must
fetch a certificate without TLS. It was trusting HTTP
for this when a more secure encrypted LDAP channel
was also available.
https://www.samba.org/samba/security/CVE-2026-3012.html
o CVE-2026-3238: Denial of service against AD DC WINS server
The WINS server component of the Active
Directory Domain controller code in Samba
is vulnerable to a NULL pointer dereference
and crash caused by a unauthenticated UDP
packet.
https://www.samba.org/samba/security/CVE-2026-3238.html
o CVE-2026-4408: Unauthenticated Remote Code Execution in Samba DCE/RPC SAMR
server
Samba file servers and classic (non-AD) domain controllers
with samba-dcerpcd started as a system service and with a
"check password script" that has the %u substitution
character are vulnerable to a remote code execution.
https://www.samba.org/samba/security/CVE-2026-4408.html
o CVE-2026-4480: Unauthenticated Remote Code Execution in Samba printing
subsystem
Samba print servers with a "print command"
that has the %J substitution character
are vulnerable to a Remote Code Execution.
https://www.samba.org/samba/security/CVE-2026-4480.html
Changes
-------
o Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
* BUG 15997: CVE-2026-2340
* BUG 16003: CVE-2026-3012
* BUG 16033: CVE-2026-4480
* BUG 16034: CVE-2026-4408
o Pavel Kohout <pavel@aisle.com>
* BUG 15997: CVE-2026-2340
o Volker Lendecke <vl@samba.org>
* BUG 15992: CVE-2026-1933
* BUG 16012: CVE-2026-3238
o Stefan Metzmacher <metze@samba.org>
* BUG 15992: CVE-2026-1933
* BUG 16033: CVE-2026-4480
* BUG 16034: CVE-2026-4408
* BUG 16059: (4.23-only) CVE-2026-40170: thirdparty ngtcp2 needs to be updated
* BUG 16073: (4.22/23-only) Winbind can change Ownership Of / To A User Who
has Homedir / In passwd
comment:4 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
I'm going to reassign these to the book for now so whoever wants to do them can do them.
In the meantime I will continue working on rivendell, but I do not want to continue holding the project back on important issues.
comment:5 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:6 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Fixed at b562b848e312a6a97cf3b8869de5e9b80ea3cf6a
Reassigning to SecurityAdvisory for an advisory to be filed
comment:7 by , 3 months ago
| Milestone: | 13.1 → 98-Security |
|---|
Note:
See TracTickets
for help on using tickets.

Now 4.24.2, which includes a CVE fix for the bundled ngtcp2 library
Changes since 4.24.1 -------------------- o Vinit Agnihotri <vagnihot@redhat.com> * BUG 16038: Samba 4.24 with cups can't get queue and shows errors about fetch_share_cache_time o Thales Antunes de Oliveira Barretto <thales.barretto.git@gmail.com> * BUG 16043: Fix a directory file descriptor leak in vfs_glusterfs that caused unbounded memory growth on the GlusterFS brick with persistent SMB2 connections. o Ralph Boehme <slow@samba.org> * BUG 16030: Windows Offline Files fails with permission error when directory has the read‑only attribute set o Pavel Filipenský <pfilipensky@samba.org> * BUG 15991: samba not triggering mount of zfs snapshot in dataset .zfs/snapshots/<snapname> directory * BUG 15999: net ads join still fails with multiple DCs o Björn Jacke <bjacke@samba.org> * BUG 16076: samba-tool shows wrong format specifiers for timestamp attributes o Stefan Metzmacher <metze@samba.org> * BUG 14638: restrict anonymous = 2 breaks RODC functionality * BUG 15973: smbpasswd can crash winbindd on an AD DC * BUG 15995: smbd does not cleanup on disconnect of the transport connection on lease break errors * BUG 16059: CVE-2026-40170: thirdparty ngtcp2 needs to be updated * BUG 16067: Require NTLMv2 session security on Windows makes trusts to Samba unusable * BUG 16073: Winbind can change Ownership Of / To A User Who has Homedir / In passwd o Andreas Schneider <asn@samba.org> * BUG 15987: Winbind lsa_OpenPolicy() fails on lsa connection setup with: NT_STATUS_RPC_CANNOT_SUPPORT o Shachar Sharon <ssharon@redhat.com> * BUG 16068: CTDB read-only record handling contains use after free and resource leak bugs