UbuntuUpdates.org

Package "samba"

Name: samba

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • clustered database to store temporary data
  • LDAP-like embedded database - tools
  • tools for viewing and manipulating the Windows registry
  • Samba control files to run AD Domain Controller

Latest version: 2:4.22.3+dfsg-4ubuntu2.1
Release: questing (25.10)
Level: updates
Repository: universe

Links



Other versions of "samba" in Questing

Repository Area Version
base main 2:4.22.3+dfsg-4ubuntu2
base universe 2:4.22.3+dfsg-4ubuntu2
security main 2:4.22.3+dfsg-4ubuntu2.1
security universe 2:4.22.3+dfsg-4ubuntu2.1
updates main 2:4.22.3+dfsg-4ubuntu2.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2:4.22.3+dfsg-4ubuntu2.1 2025-10-16 17:07:48 UTC

  samba (2:4.22.3+dfsg-4ubuntu2.1) questing-security; urgency=medium

  * SECURITY UPDATE: uninitialized memory disclosure via vfs_streams_xattr
    - debian/patches/CVE-2025-9640-1.patch: add torture test for inserting
      hole in stream in source3/selftest/tests.py, source4/torture/*.
    - debian/patches/CVE-2025-9640-2.patch: fix unitialized write in
      source3/modules/vfs_streams_xattr.c.
    - CVE-2025-9640
  * SECURITY UPDATE: command injection via WINS server hook script
    - debian/patches/CVE-2025-10230-1.patch: check that wins hook sanitizes
      names in python/samba/tests/usage.py, selftest/*, source4/torture/*,
      testprogs/blackbox/wins_hook_test.
    - debian/patches/CVE-2025-10230-2.patch: restrict names fed to shell in
      source4/nbt_server/wins/wins_hook.c.
    - CVE-2025-10230

 -- Marc Deslauriers <email address hidden> Thu, 09 Oct 2025 08:57:10 -0400

CVE-2025-9640 A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows
CVE-2025-10230 Command injection via WINS server hook script



About   -   Send Feedback to @ubuntu_updates