Описание
Security update for samba
This update for samba fixes the following issues:
- CVE-2025-9640: Fixed uninitialized memory disclosure via vfs_streams_xattr (bsc#1251279).
- CVE-2025-10230: Fixed command Injection in WINS server hook script (bsc#1251280).
Update to 4.21.8:
- netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with SysvolReady=0; (bso#14981).
- getpwuid does not shift to new DC when current DC is down; (bso#15844).
- Windows security hardening locks out schannel'ed netlogon dc calls like netr_DsRGetDCName; (bso#15876).
- kinit command is failing with Missing cache Error; (bso#15840).
- Figuring out the DC name from IP address fails and breaks fork_domain_child(); (bso#15891).
- Delayed leader broadcast can block ctdb forever; (bso#15892).
- 'net ads group' failed to list domain groups; (bso#15900).
- Apparently there is a conflict between shadow_copy2 module and virusfilter (action quarantine); (bso#15663).
- Fix handling of empty GPO link; (bso#15877).
- SMB ACL inheritance doesn't work for files created; (bso#15880).
Список пакетов
Container suse/multi-linux-manager/5.1/x86_64/server:latest
Container suse/samba-client:latest
Container suse/samba-server:latest
Container suse/samba-toolbox:latest
Image SLES15-SP7-Azure-3P
Image SLES15-SP7-Azure-Basic
Image SLES15-SP7-Azure-Standard
Image SLES15-SP7-BYOS-Azure
Image SLES15-SP7-BYOS-EC2
Image SLES15-SP7-BYOS-GCE
Image SLES15-SP7-CHOST-BYOS-Aliyun
Image SLES15-SP7-CHOST-BYOS-Azure
Image SLES15-SP7-CHOST-BYOS-EC2
Image SLES15-SP7-CHOST-BYOS-GCE
Image SLES15-SP7-CHOST-BYOS-GDC
Image SLES15-SP7-CHOST-BYOS-SAP-CCloud
Image SLES15-SP7-EC2
Image SLES15-SP7-EC2-ECS-HVM
Image SLES15-SP7-GCE
Image SLES15-SP7-GCE-3P
Image SLES15-SP7-HPC-Azure
Image SLES15-SP7-HPC-BYOS-Azure
Image SLES15-SP7-HPC-BYOS-EC2
Image SLES15-SP7-HPC-BYOS-GCE
Image SLES15-SP7-Hardened-BYOS-Azure
Image SLES15-SP7-Hardened-BYOS-EC2
Image SLES15-SP7-Hardened-BYOS-GCE
Image SLES15-SP7-SAP-Azure
Image SLES15-SP7-SAP-Azure-3P
Image SLES15-SP7-SAP-Azure-LI-BYOS-Production
Image SLES15-SP7-SAP-Azure-VLI-BYOS-Production
Image SLES15-SP7-SAP-BYOS-Azure
Image SLES15-SP7-SAP-BYOS-EC2
Image SLES15-SP7-SAP-BYOS-GCE
Image SLES15-SP7-SAP-EC2
Image SLES15-SP7-SAP-GCE
Image SLES15-SP7-SAP-GCE-3P
Image SLES15-SP7-SAP-Hardened-Azure
Image SLES15-SP7-SAP-Hardened-BYOS-Azure
Image SLES15-SP7-SAP-Hardened-BYOS-EC2
Image SLES15-SP7-SAP-Hardened-BYOS-GCE
Image SLES15-SP7-SAP-Hardened-GCE
Image SLES15-SP7-SAPCAL-Azure
Image SLES15-SP7-SAPCAL-EC2
Image SLES15-SP7-SAPCAL-GCE
Image server-image
Image server-image-sles15sp7
SUSE Linux Enterprise High Availability Extension 15 SP7
SUSE Linux Enterprise Module for Basesystem 15 SP7
Ссылки
- Link for SUSE-SU-2025:3676-1
- E-Mail link for SUSE-SU-2025:3676-1
- SUSE Security Ratings
- SUSE Bug 1251279
- SUSE Bug 1251280
- SUSE CVE CVE-2025-10230 page
- SUSE CVE CVE-2025-9640 page
Описание
A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller's wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process.
Затронутые продукты
Ссылки
- CVE-2025-10230
- SUSE Bug 1251280
Описание
A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.
Затронутые продукты
Ссылки
- CVE-2025-9640
- SUSE Bug 1251279