[ubuntu/noble-security] samba 2:4.19.5+dfsg-4ubuntu9.7 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Tue Jul 28 11:36:39 UTC 2026
samba (2:4.19.5+dfsg-4ubuntu9.7) noble-security; urgency=medium
* SECURITY UPDATE: unexpected / directory permissions change
- debian/patches/CVE-2026-15779.patch: pam_winbind: only chown the home
directory if it was created in nsswitch/pam_winbind.c.
- CVE-2026-15779
* SECURITY UPDATE: July 2026 security updates
- debian/patches/security-202607-*.patch
- CVE-2026-6949 - TSIG packet with name compression can crash DNS.
- CVE-2026-58216 - An authenticated user could possibly crash a KDC
process.
- CVE-2026-58218 - DNS signing DoS via TKEY name cache exhaustion.
- CVE-2026-58221 - Samba AD authenticated LDAP access domain takeover.
- CVE-2026-58222 - Samba AD LDAP Compare filter injection and trusted-
request confusion disclose protected attributes.
- CVE-2026-58224 - The CTDB protocol has bounds checking issues.
Date: 2026-07-24 17:29:15.285864+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/samba/2:4.19.5+dfsg-4ubuntu9.7
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list