6.6 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): HIGH
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Samba: smbd doesn't pick up group membership changes when re-authenticating an expired smb session
A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.
References
- https://www.samba.org/samba/security/CVE-2025-0620.html
- https://access.redhat.com/security/cve/CVE-2025-0620 x_refsource_REDHAT vdb-entry
- RHBZ#2370453 issue-tracking x_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2025/06/03/8
- https://access.redhat.com/security/cve/CVE-2025-0620 x_refsource_REDHAT vdb-entry
- RHBZ#2370453 issue-tracking x_refsource_REDHAT
- https://www.samba.org/samba/security/CVE-2025-0620.html
- http://www.openwall.com/lists/oss-security/2025/06/03/8
- https://access.redhat.com/security/cve/CVE-2025-0620 x_refsource_REDHAT vdb-entry
- RHBZ#2370453 issue-tracking x_refsource_REDHAT
- https://www.samba.org/samba/security/CVE-2025-0620.html
- http://www.openwall.com/lists/oss-security/2025/06/03/8
- https://access.redhat.com/security/cve/CVE-2025-0620 x_refsource_REDHAT vdb-entry
- RHBZ#2370453 issue-tracking x_refsource_REDHAT
- https://www.samba.org/samba/security/CVE-2025-0620.html
- http://www.openwall.com/lists/oss-security/2025/06/03/8
Affected products
- <4.21.6
Matching in nixpkgs
pkgs.samba4
Standard Windows interoperability suite of programs for Linux and Unix
-
nixos-unstable -
- nixpkgs-unstable 4.22.3
pkgs.sambaFull
Standard Windows interoperability suite of programs for Linux and Unix
-
nixos-unstable -
- nixpkgs-unstable 4.22.3
pkgs.samba4Full
Standard Windows interoperability suite of programs for Linux and Unix
-
nixos-unstable -
- nixpkgs-unstable 4.22.3
Package maintainers
-
@aneeshusa Aneesh Agrawal <aneeshusa@gmail.com>
-
@jbedo Justin Bedő <cu@cua0.org>