Samba 4.15.2, 4.14.10, 4.13.14 security releases apply to AD domain scenerios only
Samba 4.15.2, 4.14.10, 4.13.14 security releases apply to AD domain scenerios only
Posted Nov 14, 2021 12:38 UTC (Sun) by docontra (guest, #153758)In reply to: Samba 4.15.2, 4.14.10, 4.13.14 security releases apply to AD domain scenerios only by pabs
Parent article: Samba 4.15.2, 4.14.10, 4.13.14 security releases available
From reading the security advisories, Samba clients joined to AD may be vulnerable to CVE-2016-2124 (IIUC, it's the protocol vulnerability that caused Microsoft to disable SMB1 by default in later Windows 10 releases; requires specific client configuration to trigger), CVE-2020-25717 (second highest CVSSv3 rating, but some vulnerabilities were not rated) and CVE-2021-23192 (lowest CVSSv3 rated vulnerability).
The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:
Note: you can avoid this step in the future by logging into your LWN account.
