samba-4.23.5-10.el9_8
エラータID: AXSA:2026-1321:09
Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information.
Security Fix(es):
* samba: Missing access check on reparse point operations (CVE-2026-1933)
* samba: vfs_worm does not block directory modification (CVE-2026-2340)
* samba: group policy certificate enrollment uses without validation (CVE-2026-3012)
* samba: Samba: Remote Code Execution in printing subsystem via unescaped job description (CVE-2026-4480)
* ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake (CVE-2026-40170)
* samba: Remote Code Execution in SAMR (CVE-2026-4408)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-1933
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.
CVE-2026-2340
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
CVE-2026-3012
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
CVE-2026-40170
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client.
CVE-2026-4408
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
CVE-2026-4480
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
Update packages.
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client.
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
N/A
SRPMS
- samba-4.23.5-10.el9_8.src.rpm
MD5: c709a5cbc9b578a76d5bc271128d75d9
SHA-256: ba009859f340d2124fbe290081b853b6f2113a62e9c90e4b1101c168f84116fb
Size: 26.59 MB
Asianux Server 9 for x86_64
- ctdb-4.23.5-10.el9_8.x86_64.rpm
MD5: 7ca8b22c986753aa230390332a2bfa2c
SHA-256: b97230bf4cda6892a86d6f5cc61621359e62af96862cdf03f1f4e0424450ee68
Size: 867.69 kB - ldb-tools-4.23.5-10.el9_8.x86_64.rpm
MD5: 463ff482a715249dd3592fa999ee3c83
SHA-256: a99d041656d4369d97a8da1064430bb6c9e2153578ea6b151c1a4aa4aa0a2e4d
Size: 56.94 kB - libldb-4.23.5-10.el9_8.i686.rpm
MD5: 9769468091a66bf4c367450a530d5529
SHA-256: b78a55025a27abde6b44fe16c95a4f53f99a385b7a986dae9880cc23b8f23b9f
Size: 187.25 kB - libldb-4.23.5-10.el9_8.x86_64.rpm
MD5: 641fdf46b55c7e2a67630f8dc2db1104
SHA-256: f3d0b4707bc35534bf3055e9f160664efbdfba577abf8966630fa08667126bfe
Size: 185.79 kB - libldb-devel-4.23.5-10.el9_8.i686.rpm
MD5: a2af3f971fd7f12b7be84e78db926615
SHA-256: 91efed8ae4e8d43d8b25d7606646352c6da3f6f5a4b42ece9f829bd2a06bc8e3
Size: 93.91 kB - libldb-devel-4.23.5-10.el9_8.x86_64.rpm
MD5: e768293bc94ceffc5c12d88fa0de56f2
SHA-256: f7af46dd21e9b639c021b590bb9fea550bc929a5c2d2a2cc971e94afdacfbe9c
Size: 93.91 kB - libnetapi-4.23.5-10.el9_8.i686.rpm
MD5: 9514e98cb86637d798ed36027b96d471
SHA-256: 1bf715a599c1dbb41cc17880be9b1ab1008c7cfab6011db7239f3ab7c7a59780
Size: 155.72 kB - libnetapi-4.23.5-10.el9_8.x86_64.rpm
MD5: 1b938bbe355e636fec1c163f7899be19
SHA-256: 1f47990fbbf1a52420935fe2f1e71cbfd1ca4b55d3ddcb2953703f9269acd955
Size: 142.82 kB - libnetapi-devel-4.23.5-10.el9_8.i686.rpm
MD5: 67650d150c15af18842efa0401728654
SHA-256: 33aab5c32f69abf0df02ca9ecfa5590fe2527950a395a08d9a6fed45f4780309
Size: 24.45 kB - libnetapi-devel-4.23.5-10.el9_8.x86_64.rpm
MD5: b41f450d415b19c6544d3accac139715
SHA-256: 726aee1eb699d6d17d336fca0a059bd21214424129ecc487f9e8d131533dd925
Size: 24.44 kB - libsmbclient-4.23.5-10.el9_8.i686.rpm
MD5: eebe2e856c43e92bf1426f596699d6bf
SHA-256: be5ddeec00215655724ada4393f5cbeee9b2c095732c870709b4bcb1e639b844
Size: 80.75 kB - libsmbclient-4.23.5-10.el9_8.x86_64.rpm
MD5: 090d37e3b44c9c226d05ccf89bae5d71
SHA-256: 1b4f6a1cbb7d866996900d735a990afc485ddfab8da59d83b0d9515161ce8d90
Size: 75.33 kB - libsmbclient-devel-4.23.5-10.el9_8.i686.rpm
MD5: 02e8eb577578014811dd21541a3d68e9
SHA-256: 37d33023e54664fb18e94977e5f30fcfe6c6dd5536d76f0f0549900bc73f21f1
Size: 34.77 kB - libsmbclient-devel-4.23.5-10.el9_8.x86_64.rpm
MD5: 61a5ff2da444266ec8b02df5c82e9af6
SHA-256: 0c7b430ea1efac9d4f3dae825e3d7612cc0a088ce03ce373b58c16822fdb4ab1
Size: 34.75 kB - libwbclient-4.23.5-10.el9_8.i686.rpm
MD5: e6f2625ec8e013b1e42b52c296140d77
SHA-256: 17ccc7e6f7a0f4206e14a8fa614afd6e4f9f96ce5021ae9ded5d06d988e24e1b
Size: 46.31 kB - libwbclient-4.23.5-10.el9_8.x86_64.rpm
MD5: 75e0ced053ca5849d15fee54af22715a
SHA-256: da50af7ae4efc93c2c2336267dbb656393e527f2549b902d15631e40947726e8
Size: 43.59 kB - libwbclient-devel-4.23.5-10.el9_8.i686.rpm
MD5: fa5a1296c5af1279ebcbec890bef918c
SHA-256: a351cabb71c38283fe14c65763afac631365cea3a1880600dec4c8d016abd2aa
Size: 23.26 kB - libwbclient-devel-4.23.5-10.el9_8.x86_64.rpm
MD5: 86497dee3ea31628940d9181f5a08641
SHA-256: 3c9d0ae273ed051ab3b7a26b1ba7ef63f3e88def80c1c5f4a4a7b6ff19bba8c9
Size: 23.24 kB - python3-ldb-4.23.5-10.el9_8.i686.rpm
MD5: ca8d424346dc1cd61e6fb0c2da5fbed7
SHA-256: 45951a30c3b4bda8d97440a01cecc5c9bd06ddc4a487a49224cfa0c21f735d9c
Size: 57.42 kB - python3-ldb-4.23.5-10.el9_8.x86_64.rpm
MD5: 4ea98e5c5af4c3436fbd224bcc475419
SHA-256: 2f366d4956dd94ffecc57ce868395e67fcf6983e493e1ebc7d21b97949c912b4
Size: 54.80 kB - python3-samba-4.23.5-10.el9_8.i686.rpm
MD5: c576c357453efac31c6cf8929deb8019
SHA-256: 1b451e23c30329c4ab44cde450d5d172f230c01d3a42c8e74ac7fb7a7117a475
Size: 3.69 MB - python3-samba-4.23.5-10.el9_8.x86_64.rpm
MD5: bba668424437bad07e381e9542e07aab
SHA-256: 9fbcfc4dd561b7462d2e95f138b7c05abf39f9afe2c30cb2436f34647b1b1eec
Size: 3.88 MB - python3-samba-dc-4.23.5-10.el9_8.x86_64.rpm
MD5: 25f7bfadaf52313eb76edec91ed3472f
SHA-256: c02909908442f24bf093795c17b723c0eb43e833106ab5d07611f725a95b0bfb
Size: 353.47 kB - python3-samba-test-4.23.5-10.el9_8.x86_64.rpm
MD5: 439cd91cc03ca90f4da67fad1ba17c99
SHA-256: a020895ac58024faea923f01b8019a5a260b02f8e60d2c6aa5ccd4a8573f5c38
Size: 1.62 MB - samba-4.23.5-10.el9_8.x86_64.rpm
MD5: 5405a939f8823f0a624a14bdb8eb3f7f
SHA-256: 0621059508edef75d2ed36093b3578056744221836071a50966e22298e9cf498
Size: 853.54 kB - samba-client-4.23.5-10.el9_8.x86_64.rpm
MD5: 9b4f7fa299932b33dafa53ca20ee54f5
SHA-256: eab4ae2d7eac803353c614958ff973898671fee960ce6a627ed4e6ebd2339dde
Size: 748.24 kB - samba-client-libs-4.23.5-10.el9_8.i686.rpm
MD5: 7a57335f7339132ac3168b55c7c71cd1
SHA-256: ff51c15afe748367197160a65b822aa475ee1907f13ee54654fa135620a91306
Size: 5.98 MB - samba-client-libs-4.23.5-10.el9_8.x86_64.rpm
MD5: 4ae55860334e783a05aae07702d565d0
SHA-256: ea0608aaafc32b8e9fe94765ee049c5474ca95c17b1f28ee0d4e61f70602ff44
Size: 5.54 MB - samba-common-4.23.5-10.el9_8.noarch.rpm
MD5: be1b717cdae37ff642cd2a528d3553ae
SHA-256: c8ab6013cddd1fa5fefaa42d075c465f16b8e9ac77a06a61aa8b48459f5a6ed8
Size: 179.64 kB - samba-common-libs-4.23.5-10.el9_8.i686.rpm
MD5: 740a23b8c535ff265ce4b0d4867ab781
SHA-256: 6961a39b9abc1873e0ca5259a0222e9c7303f05d2a6246da8ccf30399910d365
Size: 114.76 kB - samba-common-libs-4.23.5-10.el9_8.x86_64.rpm
MD5: 3db919081ad87a1fb01c5666fd24fdf5
SHA-256: 9356137c6c0b80277e2325bcaa1adb5d517b4f8be66ddc000294004bcfebe8b1
Size: 104.75 kB - samba-common-tools-4.23.5-10.el9_8.x86_64.rpm
MD5: 02ccc9b6b2603b45c62ab5120c6eb86c
SHA-256: 7e8bb1e91df069eabb281e4358171d894b5a3176fa0c0b5ca32df21e0d46f511
Size: 497.14 kB - samba-dcerpc-4.23.5-10.el9_8.x86_64.rpm
MD5: 9dc65363148bbc4281e066a5efa04c64
SHA-256: 302f1f8478e09a8264eaefb63c2316d4e7a00d41dcbeab7c1950a0615c1d0107
Size: 722.21 kB - samba-dc-libs-4.23.5-10.el9_8.i686.rpm
MD5: f11808132e79185c076ad8a7f5c40e20
SHA-256: da01fcc2d5c30ae987d0238e062f4a91b977e21d2744c47fd45d0a6116c2ba6b
Size: 127.82 kB - samba-dc-libs-4.23.5-10.el9_8.x86_64.rpm
MD5: ab932c4ec98ece94e41c0bd0751d4371
SHA-256: a2bff2d0d3eb470c76b8fc0f27f42285ecbe6f70550a0af95d75535da2ecb414
Size: 117.07 kB - samba-devel-4.23.5-10.el9_8.i686.rpm
MD5: bca1d1ddbb79ceb0bd368f6117ddaece
SHA-256: 449ef6b9da2ffe541dadde4a4d2d694bd5573903c1471334733d840faa0068c9
Size: 245.65 kB - samba-devel-4.23.5-10.el9_8.x86_64.rpm
MD5: 05b13a43d108afefcf95c4667a0183b8
SHA-256: fcf422263e36fa72ba5ebce75e9ac6930a8d60c8875d313185f37158bfaa7dfc
Size: 245.77 kB - samba-gpupdate-4.23.5-10.el9_8.noarch.rpm
MD5: 9fa71d8609c2d3c5e48f52a791aba7b7
SHA-256: 9a95063650730b510504f9393544c5e02fecb3bc73be29a8740dffc145a26f4a
Size: 17.25 kB - samba-krb5-printing-4.23.5-10.el9_8.x86_64.rpm
MD5: da7248b3b4755a798cf9be87f4f8ae70
SHA-256: 2c5916a8fbdfd52ad9c671c732d4fe6d629adb10d592d70abe2e24c039e95d76
Size: 21.65 kB - samba-ldb-ldap-modules-4.23.5-10.el9_8.x86_64.rpm
MD5: a5792176745ea8704faa301e02c85f5a
SHA-256: f658a7c14ad981617b926be8ce1852d44e58fe90724791e0b37b10e3a4aba6cc
Size: 35.41 kB - samba-libs-4.23.5-10.el9_8.i686.rpm
MD5: 7a56ae46cc6fba2faf4ab215f5e63baf
SHA-256: 01daf61ac0e18dedbf51eb1f53729423835c9a0990eed842c9fa443a58b0fa14
Size: 131.89 kB - samba-libs-4.23.5-10.el9_8.x86_64.rpm
MD5: d1eaee6f8e4f7a79a1aa2ae24e18a035
SHA-256: acec58a1296d0596b33d29ccfe3ce74880be52fcff75684657546fbd44a6defc
Size: 124.79 kB - samba-pidl-4.23.5-10.el9_8.noarch.rpm
MD5: 2360719d891d792a24c0eae974de2146
SHA-256: 92ba61e472b0e7791ea91723fb8f0fff13d47ff959baf84e0576fdf006b62228
Size: 123.62 kB - samba-test-4.23.5-10.el9_8.x86_64.rpm
MD5: 1763192515d26c1a2b053a98d0d8d055
SHA-256: bf1b4296a187926f319ff019add5c84e515cabe5672c4c8f83425d0b04c9d7b0
Size: 2.40 MB - samba-test-libs-4.23.5-10.el9_8.x86_64.rpm
MD5: 2f6d5f3b96cdcf1dbd1b9d4a698806e2
SHA-256: cef47321c171c527b0fa1e1a8f93ea49d5b0a210f4f79aecce9374d88602b6ce
Size: 44.44 kB - samba-tools-4.23.5-10.el9_8.x86_64.rpm
MD5: 3b7aea24e70b9869be977f6d4b3186f7
SHA-256: 133630fe7720b082712ed2fe0933f84c2bd9f8e7799f11ef6602047d401314d7
Size: 32.71 kB - samba-usershares-4.23.5-10.el9_8.noarch.rpm
MD5: de5acb61544c973c631a051e32a8ff17
SHA-256: ca1135a68f4e9f8c6565aeb98903c87dd0cb5556335b04ff6222e5c4a2628d79
Size: 14.34 kB - samba-vfs-iouring-4.23.5-10.el9_8.x86_64.rpm
MD5: 48094ce2d0e336b77ecf906033478225
SHA-256: 2882eb442ae3f2be54ccd02cce23b10203c5c642d1d921a30fa5c02a2f2262aa
Size: 25.33 kB - samba-winbind-4.23.5-10.el9_8.x86_64.rpm
MD5: 8d37e796c1b40bbfbb2fbcde4f895df8
SHA-256: b9a33873715bb33da2b71459dd89c9ba30cc7a3f8c7a206a67f79d9dd5a52896
Size: 417.53 kB - samba-winbind-clients-4.23.5-10.el9_8.x86_64.rpm
MD5: f0e3e8ec73ee01c7403f5bac30b69768
SHA-256: 817ef06f5d02cc2b7aed4bb65216ba35888a5e530730864b636ae60a99f1ec86
Size: 81.35 kB - samba-winbind-krb5-locator-4.23.5-10.el9_8.x86_64.rpm
MD5: 0b4d6620791219b4a987e16173c37206
SHA-256: b81377eb6f52bb753d6cc7a1252596138998c660debb2b3034aacd69bb79ea2e
Size: 28.69 kB - samba-winbind-modules-4.23.5-10.el9_8.i686.rpm
MD5: 49869322eaa27e53940a9a8efc4d2294
SHA-256: 0b654129885778dc1b0738dd149601fca9ccdbe63542bc06489622a1b3ca690d
Size: 99.09 kB - samba-winbind-modules-4.23.5-10.el9_8.x86_64.rpm
MD5: ca9902c43591d30dba90841ee66d7f58
SHA-256: 919504bcb49268146705d58a478585ed9816e5bfb11f70245d5ae6b5fa8f8be8
Size: 96.53 kB - samba-winexe-4.23.5-10.el9_8.x86_64.rpm
MD5: bee46d45fda369023228d0a054935f65
SHA-256: 1fd32a1b13160ecbeb6c201c8d0d6584367db7c9c771e2fc6675aa4c5d028191
Size: 83.52 kB