SUSE-SU-2025:3676-1
Dashboard / Vulnerabilities / SUSE-SU-2025:3676-1
SUSE-SU-2025:3676-1
Summary: Security update for samba
Details: This update for samba fixes the following issues: - CVE-2025-9640: Fixed uninitialized memory disclosure via vfs_streams_xattr (bsc#1251279). - CVE-2025-10230: Fixed command Injection in WINS server hook script (bsc#1251280). Update to 4.21.8: * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with SysvolReady=0; (bso#14981). * getpwuid does not shift to new DC when current DC is down; (bso#15844). * Windows security hardening locks out schannel'ed netlogon dc calls like netr_DsRGetDCName; (bso#15876). * kinit command is failing with Missing cache Error; (bso#15840). * Figuring out the DC name from IP address fails and breaks fork_domain_child(); (bso#15891). * Delayed leader broadcast can block ctdb forever; (bso#15892). * 'net ads group' failed to list domain groups; (bso#15900). * Apparently there is a conflict between shadow_copy2 module and virusfilter (action quarantine); (bso#15663). * Fix handling of empty GPO link; (bso#15877). * SMB ACL inheritance doesn't work for files created; (bso#15880).
References: https://www.suse.com/support/update/announcement/2025/suse-su-20253676-1/, https://bugzilla.suse.com/1251279, https://bugzilla.suse.com/1251280, https://www.suse.com/security/cve/CVE-2025-10230, https://www.suse.com/security/cve/CVE-2025-9640
Affected packages
Package
Name: samba
Purl: pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7
Affected ranges
Type: ECOSYSTEM
Events:
