{"id":"SUSE-SU-2023:2929-1","summary":"Security update for samba","details":"This update for samba fixes the following issues:\n\n  samba was updated to version 4.17.9:\n\n  - CVE-2022-2127: Fixed issue where lm_resp_len was not checked properly in winbindd_pam_auth_crap_send (bsc#1213174).\n  - CVE-2023-34966: Fixed samba spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability (bsc#1213173).\n  - CVE-2023-34967: Fixed samba spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability (bsc#1213172).\n  - CVE-2023-34968: Fixed spotlight server-side Share Path Disclosure (bsc#1213171).\n  - CVE-2023-3347: Fixed issue where SMB2 packet signing not enforced (bsc#1213170).\n  - CVE-2020-25720: Fixed issue where creating child permission allowed full write to all attributes (bsc#1213386).\n\n  Bugfixes:\n\n  - Fixed trust relationship failure (bsc#1213384).\n  - Backported --pidl-developer fixes.\n  - Fixed smbd_scavenger crash when service smbd is stopped.\n  - Fixed issue where vfs_fruit might cause a failing open for delete.\n  - Fixed named crashes on DLZ zone update.\n  - Fixed issue where winbind recurses into itself via rpcd_lsad.\n  - Fixed cli_list looping 100% CPU against pre-lanman2 servers.\n  - Fixed smbclient leaks fds with showacls.\n  - Fixed aes256 smb3 encryption algorithms not allowed in smb3_sid_parse().\n  - Fixed winbindd getting stuck on NT_STATUS_RPC_SEC_PKG_ERROR.\n  - Fixed smbget memory leak if failed to download files recursively.\n  - Fixed log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower.\n  - Fixed floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c.\n  - Fixed test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners.\n  - Reduce flapping of ridalloc test.\n  - Fixed unreliable large_ldap test.\n  - Fixed filename parser not checking veto files smb.conf parameter.\n  - Fixed mdssvc may crash when initializing.\n  - Fixed broken large directory optimization for non-lcomp path elements\n  - Fixed streams_depot failing to create streams.\n  - Fixed shadow_copy2 and streams_depot issues.\n  - Fixed wbinfo -u fails on ad dc with \u003e1000 users.\n  - Fixed winbindd idmap child contacting the domain controller without a need.\n  - Fixed idmap_autorid may fail to map sids of trusted domains for the first time.\n  - Fixed idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings.\n  - Fixed net ads search -P doesn't work against servers in other domains.\n  - Fixed DS ACEs might be inherited to unrelated object classes.\n  - Fixed temporary smbXsrv_tcon_global.tdb can't be parsed.\n  - Fixed setting veto files = /.*/ breaking listing directories (bsc#1212375).\n  - Fixed dsgetdcname assuming local system uses IPv4.\n","modified":"2026-03-11T07:24:24.880839Z","published":"2023-07-21T08:09:09Z","related":["CVE-2020-25720","CVE-2022-2127","CVE-2023-3347","CVE-2023-34966","CVE-2023-34967","CVE-2023-34968"],"upstream":["CVE-2020-25720","CVE-2022-2127","CVE-2023-3347","CVE-2023-34966","CVE-2023-34967","CVE-2023-34968"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20232929-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212375"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213170"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213171"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213172"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213173"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213174"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213384"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213386"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25720"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-2127"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-3347"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-34966"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-34967"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-34968"}],"affected":[{"package":{"name":"samba","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP5","purl":"pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1"}]}],"ecosystem_specific":{"binaries":[{"samba-client-libs-32bit":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-libs-32bit":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-client-libs":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-devel":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-libs-python3":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-python3":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-winbind-libs-32bit":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","libsamba-policy-devel":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","libsamba-policy0-python3":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-ceph":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-gpupdate":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-ldb-ldap":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-libs":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-winbind-libs":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","libsamba-policy-python3-devel":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-client":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-tool":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-winbind":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2929-1.json"}},{"package":{"name":"samba","ecosystem":"SUSE:Linux Enterprise High Availability Extension 15 SP5","purl":"pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1"}]}],"ecosystem_specific":{"binaries":[{"ctdb":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2929-1.json"}},{"package":{"name":"samba","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1"}]}],"ecosystem_specific":{"binaries":[{"samba-devel-32bit":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-devel":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-libs-32bit":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-libs-python3-32bit":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-winbind-libs":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-winbind":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","ctdb-pcp-pmda":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","libsamba-policy-python3-devel":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","libsamba-policy0-python3-32bit":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-ceph":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-client-libs":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-gpupdate":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-libs-python3":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-python3":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","ctdb":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","libsamba-policy-devel":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-client-32bit":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-client-libs-32bit":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-client":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-doc":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-tool":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-winbind-libs-32bit":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","libsamba-policy0-python3":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-ldb-ldap":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-libs":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba-test":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1","samba":"4.17.9+git.367.dae41ffdd1f-150500.3.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2929-1.json"}}],"schema_version":"1.7.5"}