A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.
CVSS Details
- CVSS 3.1 Base Score: 4.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade samba | Nov 11, 2025 | Jun 6, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 6, 2025 |
| Debian | — | Upgrade samba | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 6, 2025 |
| Suse | — | Upgrade samba-ad-dcUpgrade samba-gpupdateUpgrade ctdb-pcp-pmdaUpgrade samba-winbindUpgrade samba-winbind-libs-32bitUpgrade python3-ldbUpgrade samba-dcerpcUpgrade samba-ad-dc-libsUpgrade samba-clientUpgrade ctdbUpgrade sambaUpgrade libldb-develUpgrade samba-toolUpgrade samba-docUpgrade samba-libs-python3Upgrade samba-libsUpgrade samba-ldb-ldapUpgrade libldb2Upgrade samba-python3Upgrade samba-client-libs-32bitUpgrade ldb-toolsUpgrade samba-dsdb-modulesUpgrade samba-client-libsUpgrade samba-develUpgrade samba-winbind-libsUpgrade samba-libs-32bitUpgrade samba-cephUpgrade libldb2-32bit | Jul 7, 2025 | Jun 6, 2025 |
| Ubuntu | — | Upgrade samba | Jun 11, 2025 | Jun 6, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub