Public bug reported:

samba (2:4.24.6+dfsg-1) unstable; urgency=medium

  * debian/upstream/signing-key.asc: update
  * new upstream stable.bugfix release:
   - https://bugzilla.samba.org/show_bug.cgi?id=15978:
     leases torture test flappy (marked flappy)
   - https://bugzilla.samba.org/show_bug.cgi?id=15994:
     CTDB doesn't send tickle ACKs when taking over a released IP
   - https://bugzilla.samba.org/show_bug.cgi?id=16065:
     Memory leak in DRS when replication fails
   - https://bugzilla.samba.org/show_bug.cgi?id=16077:
     witness test flappy needs to be fixed
   - https://bugzilla.samba.org/show_bug.cgi?id=16093:
     temporary read of unrelated or non-existing memory in s3 dfs server
   - https://bugzilla.samba.org/show_bug.cgi?id=16094:
     source4/dsdb/samdb/cracknames.c doesn't use ldb_binary_encode_string()
     consistently
   - https://bugzilla.samba.org/show_bug.cgi?id=16152:
     CTDB can run nested elections, in rare circumstances
   - https://bugzilla.samba.org/show_bug.cgi?id=16153:
     dsgetdcname() may not detect an active directory domain if the
     netbios domain name is given and nmbd nor the nbt service is available
   - https://bugzilla.samba.org/show_bug.cgi?id=16176:
     vfs_ceph_snapshots: smbd panics on snapshot access for a share
     mounted at the CephFS root ("/")
   - https://bugzilla.samba.org/show_bug.cgi?id=16186:
     vfs_ceph_new: smbd crashes when mixing proxy and non-proxy CephFS shares
   - https://bugzilla.samba.org/show_bug.cgi?id=16191:
     race condition in pthreadpool when forking
   - https://bugzilla.samba.org/show_bug.cgi?id=16199:
     ndr_{push,pull,print}_{timeval,timespec} encode/decode the value twice
  * d/samba-libs.symbols: add new ndr symbols

 -- Michael Tokarev <[email protected]>  Thu, 13 Aug 2026 19:14:56 +0300

samba (2:4.24.5+dfsg-1) unstable; urgency=medium

  * new upstream Jul-2026 secrity release, fixing the following issues:
    CVE-2026-6949: TSIG packet with name compression can crash DNS
      https://www.samba.org/samba/security/CVE-2026-6949.html
    CVE-2026-58216: An authenticated user could possibly crash a KDC process
      https://www.samba.org/samba/security/CVE-2026-58216.html
    CVE-2026-58218: DNS signing DoS via TKEY name cache exhaustion
      https://www.samba.org/samba/security/CVE-2026-58218.html
    CVE-2026-58221: Samba AD authenticated LDAP access domain takeover
      https://www.samba.org/samba/security/CVE-2026-58221.html
    CVE-2026-58222: Samba AD LDAP Compare filter injection and
      trusted-request confusion disclose protected attributes
      https://www.samba.org/samba/security/CVE-2026-58222.html
    CVE-2026-58224: The CTDB protocol has bounds checking issues
      https://www.samba.org/samba/security/CVE-2026-58224.html

 -- Michael Tokarev <[email protected]>  Tue, 28 Jul 2026 14:09:41 +0300

** Affects: samba (Ubuntu)
     Importance: Undecided
     Assignee: Andreas Hasenack (ahasenack)
         Status: In Progress


** Tags: needs-merge

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2164694

Title:
  Second samba merge for stonking

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/samba/+bug/2164694/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to