Package samba: Information

  • Default inline alert: Version in the repository: 4.19.6-alt1

Source package: samba
Version: 4.17.8-alt1
Latest version according to Repology
Build time:  May 29, 2023, 06:39 PM in the task #321564
Category: System/Servers
Report package bug
License: GPLv3+ and LGPLv3+
Summary: The Samba4 CIFS and AD client and server suite
Description: 
Samba is the standard Windows interoperability suite of programs for Linux and Unix.

List of rpms provided by this srpm:
admx-samba (noarch)
libldb-modules-ldap (x86_64, ppc64le, i586, armh, aarch64)
libldb-modules-ldap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient-devel (x86_64, ppc64le, i586, armh, aarch64)
libwbclient (x86_64, ppc64le, i586, armh, aarch64)
libwbclient-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libwbclient-devel (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba-devel (x86_64, ppc64le, i586, armh, aarch64)
samba (x86_64, ppc64le, i586, armh, aarch64)
samba-client (x86_64, ppc64le, i586, armh, aarch64)
samba-client-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-common (noarch)
samba-common-client (noarch)
samba-common-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-common-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-common-tools (x86_64, ppc64le, i586, armh, aarch64)
samba-common-tools-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-ctdb (x86_64, ppc64le, i586, armh, aarch64)
samba-ctdb-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dc (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-client (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-common (noarch)
samba-dc-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-mitkrb5 (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-mitkrb5-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dcerpc (x86_64, ppc64le, i586, armh, aarch64)
samba-dcerpc-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-devel (x86_64, ppc64le, i586, armh, aarch64)
samba-doc (noarch)
samba-gpupdate (x86_64, ppc64le, i586, armh, aarch64)
samba-krb5-printing (x86_64, ppc64le, i586, armh, aarch64)
samba-krb5-printing-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-pidl (noarch)
samba-test (x86_64, ppc64le, i586, armh, aarch64)
samba-test-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-usershares (x86_64, ppc64le, i586, armh, aarch64)
samba-util-private-headers (x86_64, ppc64le, i586, armh, aarch64)
samba-vfs-cephfs (x86_64, ppc64le, aarch64)
samba-vfs-cephfs-debuginfo (x86_64, ppc64le, aarch64)
samba-vfs-glusterfs (x86_64, ppc64le, i586, armh, aarch64)
samba-vfs-glusterfs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-vfs-snapper (x86_64, ppc64le, i586, armh, aarch64)
samba-vfs-snapper-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-clients (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-clients-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-common (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-localauth (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-localauth-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-locator (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-locator-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
task-samba-dc (noarch)
task-samba-dc-mitkrb5 (noarch)

Maintainer: Evgeny Sinelnikov



    1. libxslt
    2. /proc
    3. libncurses-devel
    4. ceph-devel
    5. /usr/bin/rpcgen
    6. dblatex
    7. libcap-devel
    8. python3-devel
    9. netpbm
    10. libpam-devel
    11. python3-module-dns
    12. libcups-devel
    13. python3-module-markdown
    14. libdbus-devel
    15. python3-module-pyldb-devel
    16. libpopt-devel
    17. python3-module-talloc-devel
    18. python3-module-tdb
    19. python3-module-tevent
    20. libe2fs-devel
    21. docbook-style-xsl
    22. glibc-devel
    23. glibc-kernheaders
    24. libreadline-devel
    25. flex
    26. html2text
    27. libglusterfs-api-devel
    28. libssl-devel
    29. gawk
    30. libgnutls-devel
    31. libacl-devel
    32. rpm-build-python3
    33. libarchive-devel >= 3.1.2
    34. libgpgme-devel
    35. libattr-devel
    36. libavahi-devel
    37. perl-JSON
    38. libgtk+2-devel
    39. perl-Parse-Yapp
    40. perl-devel
    41. libiniparser-devel
    42. libjansson-devel
    43. tracker-devel
    44. xsltproc
    45. libkrb5-devel
    46. libldap-devel
    47. libldb-devel = 2.6.2
    48. zlib-devel
    49. libtasn1-devel
    50. libtasn1-utils
    51. libtirpc-devel
    52. libtdb-devel >= 1.4.7
    53. libtevent-devel >= 0.13.0
    54. libsystemd-devel
    55. krb5-kdc
    56. libtalloc-devel >= 2.3.4
    57. libuuid-devel

Last changed


May 21, 2023 Evgeny Sinelnikov 4.17.8-alt1
- Update to maintenance release of Samba 4.18:
  + log flood: smbd_calculate_access_mask_fsp: Access denied: message level
    should be lower (Samba#15302).
  + Floating point exception (FPE) via cli_pull_send at
    source3/libsmb/clireadwrite.c (Samba#15306).
  + Reduce flapping of ridalloc test (Samba#15329).
  + large_ldap test is unreliable (Samba#15351).
  + New filename parser doesn't check veto files smb.conf parameter (Samba#15143).
  + mdssvc may crash when initializing (Samba#15354).
  + Large directory optimization broken for non-lcomp path elements (Samba#15313).
  + streams_depot fails to create streams (Samba#15357).
  + shadow_copy2 and streams_depot don't play well together (Samba#15358).
  + wbinfo -u fails on ad dc with >1000 users (Samba#15366).
  + winbindd idmap child contacts the domain controller without a
    need (Samba#15317).
  + idmap_autorid may fail to map sids of trusted domains for the first
    time (Samba#15318).
  + idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings (Samba#15319).
  + net ads search -P doesn't work against servers in other domains (Samba#15323).
  + DS ACEs might be inherited to unrelated object classes (Samba#15338).
  + Temporary smbXsrv_tcon_global.tdb can't be parsed (Samba#15353).
  + Setting veto files = /.*/ break listing directories (Samba#15360).
  + CVE-2020-25720 [SECURITY] Create Child permission should not
    allow full write to all attributes (additional changes) (Samba#14810).
  + Reduce flapping of ridalloc test (Samba#15329).
  + dsgetdcname: assumes local system uses IPv4 (Samba#15325).
March 29, 2023 Evgeny Sinelnikov 4.17.7-alt1
- Update to maintenance release of Samba 4.17 with update libldb to 2.6.2:
  + ldb wildcard matching makes excessive allocations (Samba#15331).

- Security fixes (Samba#15276, Samba#15270, Samba#15315, Samba#14810):
  + CVE-2023-0225: An incomplete access check on dnsHostName allows authenticated
                   but otherwise unprivileged users to delete this attribute from
                   any object in the directory.
                   https://www.samba.org/samba/security/CVE-2023-0225.html

  + CVE-2023-0922: The Samba AD DC administration tool, when operating against a
                   remote LDAP server, will by default send new or reset
                   passwords over a signed-only connection.
                   https://www.samba.org/samba/security/CVE-2023-0922.html

  + CVE-2023-0614: The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919
                   Confidential attribute disclosure via LDAP filters was
                   insufficient and an attacker may be able to obtain
                   confidential BitLocker recovery keys from a Samba AD DC.
                   Installations with such secrets in their Samba AD should
                   assume they have been obtained and need replacing.
                   https://www.samba.org/samba/security/CVE-2023-0614.html

  + CVE-2020-25720 Create Child permission should not allow full write to all
                   attributes (additional changes).
March 15, 2023 Evgeny Sinelnikov 4.17.6-alt1
- Update to maintenance release of Samba 4.17:
  + streams_xattr is creating unexpected locks on folders (Samba#15314).
  + Use of the Azure AD Connect cloud sync tool is now supported for password
    hash synchronisation, allowing Samba AD Domains to synchronise passwords
    with this popular cloud environment (Samba#10635).
  + New samba-dcerpc architecture does not scale gracefully (Samba#15310).
  + vfs_ceph incorrectly uses fsp_get_io_fd() instead of fsp_get_pathref_fd()
    in close and fstat (Samba#15307).
  + fd_load() function implicitly closes the fd where it should not (Samba#15311).
- Revert not treat of missing include file as an error in handle_include().
  This behavior differs between the source3 and source4 parts of Samba.
  So, it should be the same and just not an error (Closes #44214).