Merge samba from Debian unstable for mantic
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
samba (Ubuntu) |
Fix Released
|
High
|
Andreas Hasenack |
Bug Description
2:4.18.5+dfsg-1 (patches unapplied)
Imported using git-ubuntu import.
Notes (changelog):
* new upstream stable/security release 4.18.5, including:
o CVE-2022-2127: When winbind is used for NTLM authentication,
a maliciously crafted request can trigger an out-of-bounds read
in winbind and possibly crash it.
https:/
o CVE-2023-3347: SMB2 packet signing is not enforced if an admin
configured "server signing = required" or for SMB2 connections to
Domain Controllers where SMB2 packet signing is mandatory.
https:/
o CVE-2023-34966: An infinite loop bug in Samba's mdssvc RPC service
for Spotlight can be triggered by an unauthenticated attacker by
issuing a malformed RPC request.
https:/
o CVE-2023-34967: Missing type validation in Samba's mdssvc RPC service
for Spotlight can be used by an unauthenticated attacker to trigger
a process crash in a shared RPC mdssvc worker process.
https:/
o CVE-2023-34968: As part of the Spotlight protocol Samba discloses
the server-side absolute path of shares and files and directories
in search results.
https:/
o BUG 15418: Secure channel faulty since Windows 10/11 update 07/2023.
https:/
(this has been patched in the previous upload; Closes: #1041043)
Related branches
- git-ubuntu bot: Approve
- Lucas Kanashiro (community): Approve
- Canonical Server Reporter: Pending requested
-
Diff: 3405 lines (+3029/-6)5 files modifieddebian/changelog (+2510/-0)
debian/control (+6/-5)
debian/tests/control (+4/-0)
debian/tests/samba-ad-dc-provisioning-internal-dns (+398/-0)
debian/tests/util (+111/-1)
Changed in samba (Ubuntu): | |
importance: | Undecided → High |
summary: |
- Merge samba from Debian unstable for mantic Edit + Merge samba from Debian unstable for mantic |
Changed in samba (Ubuntu): | |
assignee: | nobody → Andreas Hasenack (ahasenack) |
This bug was fixed in the package samba - 2:4.18. 5+dfsg- 1ubuntu1
--------------- 5+dfsg- 1ubuntu1) mantic; urgency=medium
samba (2:4.18.
* Merge with Debian unstable (LP: #2028265, LP: #2027716). Remaining d/t/samba- ad-dc-provision ing-internal- dns:
changes:
- debian/control: Ubuntu i386 binary compatibility:
+ drop ceph support
+ enable the liburing vfs module, except on i386 where liburing is
not available
+ build-depend on libglusterfs-dev only on !i386 arches
- d/t/control, d/t/util,
samba AD DC provisioning and domain join tests with internal DNS
(LP #1977746, LP #2011745)
- d/t/util: reload instead of restarting samba, as it's quicker and
has the same effect we want in this test
-- Andreas Hasenack <email address hidden> Thu, 20 Jul 2023 10:15:22 -0300