Logo
componentsamba
Name
samba
Version
4.19.9
Type
library
Description
-
Licenses
GPL-3.0-or-later & LGPL-3.0-or-later & GPL-2.0-or-later
PURL
-
CPE
cpe:2.3:*:samba:samba:4.19.9:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
4.14.14
master
4.23.11

Patches#


#
Title
Author
Resolve
1
Don't check xsltproc manpages
Bian Naimeng <biannm@cn.fujitsu.com>
2
CVE-2026-4408: s3:samr-server: deny, mask and/or single
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
3
smbtorture: skip test case tfork_cmd_send
Yi Zhao <yi.zhao@windriver.com>
4
CVE-2026-4480/CVE-2026-4408: lib/util: factor out a
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
5
CVE-2026-4480/CVE-2026-4408: lib/util: add
Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
CVE-2026-4408
6
CVE-2026-4480/CVE-2026-4408: lib/util: let
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
7
Lifted from gentoo and ported to 4.4.5
Khem Raj <raj.khem@gmail.com>
8
CVE-2026-4408: s3:samr-server: only allow
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
9
Fix pyext_PATTERN for cross compilation
Yi Zhao <yi.zhao@windriver.com>
10
CVE-2026-4480/CVE-2026-4408: lib/util: add
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
11
CVE-2026-4480/CVE-2026-4408: lib/util: let log_escape()
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
12
CVE-2026-3012: do not fetch certificate over http
Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
CVE-2026-3012
13
Add options to configure the use of libbsd
Peter Kjellerstedt <pkj@axis.com>
14
Add config option without-valgrind
Changqing Li <changqing.li@windriver.com>
15
CVE-2026-3012: gp_auto_enrol: skip CAs not found in
Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
CVE-2026-3012
16
CVE-2026-4408: lib/util: introduce
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
17
CVE-2026-4480/CVE-2026-4408: lib/util: split out
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
18
CVE-2026-4480/CVE-2026-4408: s3:lib: fix potential
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
19
CVE-2026-4408: docs-xml/smbdotconf: clarify '%u' in
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
20
CVE-2026-4480/CVE-2026-4408: lib/util: remove unused
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
21
Musl does not have _r versions of getent() and getpwent()
Khem Raj <raj.khem@gmail.com>
22
CVE-2026-4480/CVE-2026-4408: s3:lib: let
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
23
CVE-2026-4408: s3:testparm: warn about 'check password
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
24
CVE-2026-4408: s3:samr-server: make
Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
CVE-2026-4408
25
Deleted settiong of python to fix the install conflict error
Lei Maohui <leimaohui@fujitsu.com>
26
CVE-2026-4480/CVE-2026-4408: lib/util: add more unsafe
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
27
CVE-2026-4480/CVE-2026-4408: lib/util: inline
Stefan Metzmacher <metze@samba.org>
CVE-2026-4408
28
do not import target module while cross compile
Changqing Li <changqing.li@windriver.com>
29
CVE-2026-4408: s3:torture: tests for password
Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
CVE-2026-4408

Vulnerabilities#


Name
Analysis
Description
Patched
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
Patched
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
Exploitable
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
Exploitable
A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.
Exploitable
A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller’s wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process.
False Positive
Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors.