A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.
CVSS Details
- CVSS 3.1 Base Score: 4.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade samba | Nov 11, 2025 | Jun 6, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 6, 2025 |
| Debian | — | Upgrade samba | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 6, 2025 |
| Suse | — | Upgrade samba-winbind-libs-32bitUpgrade samba-dcerpcUpgrade samba-docUpgrade samba-libs-python3Upgrade libldb-develUpgrade ctdbUpgrade samba-clientUpgrade python3-ldbUpgrade samba-toolUpgrade sambaUpgrade samba-ad-dc-libsUpgrade samba-gpupdateUpgrade ctdb-pcp-pmdaUpgrade samba-winbindUpgrade samba-ad-dcUpgrade samba-cephUpgrade libldb2Upgrade samba-libs-32bitUpgrade samba-client-libs-32bitUpgrade ldb-toolsUpgrade libldb2-32bitUpgrade samba-client-libsUpgrade samba-python3Upgrade samba-libsUpgrade samba-dsdb-modulesUpgrade samba-ldb-ldapUpgrade samba-develUpgrade samba-winbind-libs | Jul 7, 2025 | Jun 6, 2025 |
| Ubuntu | — | Upgrade samba | Jun 11, 2025 | Jun 6, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub