A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.
CVSS Details
- CVSS 3.1 Base Score: 4.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade samba | Nov 11, 2025 | Jun 6, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 6, 2025 |
| Debian | — | Upgrade samba | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 6, 2025 |
| Suse | — | Upgrade samba-develUpgrade samba-libs-32bitUpgrade samba-dsdb-modulesUpgrade samba-winbind-libsUpgrade samba-ldb-ldapUpgrade samba-libsUpgrade samba-client-libs-32bitUpgrade libldb2-32bitUpgrade ldb-toolsUpgrade samba-cephUpgrade samba-client-libsUpgrade samba-python3Upgrade libldb2Upgrade samba-ad-dcUpgrade sambaUpgrade samba-winbind-libs-32bitUpgrade samba-dcerpcUpgrade samba-ad-dc-libsUpgrade python3-ldbUpgrade samba-libs-python3Upgrade samba-toolUpgrade samba-clientUpgrade samba-winbindUpgrade libldb-develUpgrade ctdb-pcp-pmdaUpgrade ctdbUpgrade samba-gpupdateUpgrade samba-doc | Jul 7, 2025 | Jun 6, 2025 |
| Ubuntu | — | Upgrade samba | Jun 11, 2025 | Jun 6, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub