A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.
CVSS Details
- CVSS 3.1 Base Score: 4.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade samba | Nov 11, 2025 | Jun 6, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 6, 2025 |
| Debian | — | Upgrade samba | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 6, 2025 |
| Suse | — | Upgrade samba-libs-32bitUpgrade samba-dsdb-modulesUpgrade ldb-toolsUpgrade samba-cephUpgrade samba-client-libsUpgrade samba-python3Upgrade samba-libsUpgrade samba-client-libs-32bitUpgrade samba-ldb-ldapUpgrade samba-develUpgrade samba-winbind-libsUpgrade libldb2Upgrade libldb2-32bitUpgrade samba-winbind-libs-32bitUpgrade samba-toolUpgrade samba-clientUpgrade libldb-develUpgrade sambaUpgrade samba-dcerpcUpgrade ctdbUpgrade samba-ad-dc-libsUpgrade python3-ldbUpgrade samba-libs-python3Upgrade samba-gpupdateUpgrade ctdb-pcp-pmdaUpgrade samba-winbindUpgrade samba-ad-dcUpgrade samba-doc | Jul 7, 2025 | Jun 6, 2025 |
| Ubuntu | — | Upgrade samba | Jun 11, 2025 | Jun 6, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub