Package samba: Information

  • Default inline alert: Version in the repository: 4.20.1-alt2

Source package: samba
Version: 4.17.12-alt1
Latest version according to Repology
Build time:  Oct 18, 2023, 09:56 AM in the task #332020
Category: System/Servers
Report package bug
License: GPLv3+ and LGPLv3+
Summary: The Samba4 CIFS and AD client and server suite
Description: 
Samba is the standard Windows interoperability suite of programs for Linux and Unix.

List of rpms provided by this srpm:
admx-samba (noarch)
libldb-modules-ldap (x86_64, ppc64le, i586, armh, aarch64)
libldb-modules-ldap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient-devel (x86_64, ppc64le, i586, armh, aarch64)
libwbclient (x86_64, ppc64le, i586, armh, aarch64)
libwbclient-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libwbclient-devel (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba-devel (x86_64, ppc64le, i586, armh, aarch64)
samba (x86_64, ppc64le, i586, armh, aarch64)
samba-client (x86_64, ppc64le, i586, armh, aarch64)
samba-client-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-common (noarch)
samba-common-client (noarch)
samba-common-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-common-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-common-tools (x86_64, ppc64le, i586, armh, aarch64)
samba-common-tools-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-ctdb (x86_64, ppc64le, i586, armh, aarch64)
samba-ctdb-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dc (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-client (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-common (noarch)
samba-dc-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-mitkrb5 (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-mitkrb5-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dcerpc (x86_64, ppc64le, i586, armh, aarch64)
samba-dcerpc-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-devel (x86_64, ppc64le, i586, armh, aarch64)
samba-doc (noarch)
samba-gpupdate (x86_64, ppc64le, i586, armh, aarch64)
samba-krb5-printing (x86_64, ppc64le, i586, armh, aarch64)
samba-krb5-printing-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-pidl (noarch)
samba-test (x86_64, ppc64le, i586, armh, aarch64)
samba-test-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-usershares (x86_64, ppc64le, i586, armh, aarch64)
samba-util-private-headers (x86_64, ppc64le, i586, armh, aarch64)
samba-vfs-cephfs (x86_64, ppc64le, aarch64)
samba-vfs-cephfs-debuginfo (x86_64, ppc64le, aarch64)
samba-vfs-glusterfs (x86_64, ppc64le, i586, aarch64)
samba-vfs-glusterfs-debuginfo (x86_64, ppc64le, i586, aarch64)
samba-vfs-snapper (x86_64, ppc64le, i586, armh, aarch64)
samba-vfs-snapper-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-clients (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-clients-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-common (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-localauth (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-localauth-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-locator (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-locator-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
task-samba-dc (noarch)
task-samba-dc-mitkrb5 (noarch)

Maintainer: Evgeny Sinelnikov



    1. libcap-devel
    2. python3-module-talloc-devel
    3. python3-module-tdb
    4. python3-module-tevent
    5. /proc
    6. /usr/bin/rpcgen
    7. libcups-devel
    8. libreadline-devel
    9. docbook-style-xsl
    10. libdbus-devel
    11. glibc-devel
    12. glibc-kernheaders
    13. flex
    14. libe2fs-devel
    15. perl-JSON
    16. perl-Parse-Yapp
    17. html2text
    18. admx-lint
    19. perl-devel
    20. gawk
    21. alternatives
    22. libssl-devel
    23. ceph-devel
    24. rpm-build-python3
    25. libacl-devel
    26. rpm-macros-alternatives
    27. libglusterfs-api-devel
    28. libarchive-devel >= 3.1.2
    29. libgnutls-devel
    30. dblatex
    31. libattr-devel
    32. libavahi-devel
    33. python3-devel
    34. libgpgme-devel
    35. krb5-kdc
    36. python3-module-dns
    37. python3-module-markdown
    38. libsystemd-devel
    39. libtalloc-devel >= 2.3.4
    40. libtasn1-devel
    41. libtasn1-utils
    42. python3-module-pyldb-devel
    43. libtdb-devel >= 1.4.7
    44. libtevent-devel >= 0.13.0
    45. libiniparser-devel
    46. libtirpc-devel
    47. libuuid-devel
    48. libjansson-devel
    49. libkrb5-devel
    50. libxslt
    51. libldap-devel
    52. libldb-devel = 2.6.2
    53. xsltproc
    54. zlib-devel
    55. liblmdb-devel >= 0.9.16
    56. libpopt-devel
    57. netpbm
    58. libpam-devel
    59. libncurses-devel

Last changed


Oct. 17, 2023 Evgeny Sinelnikov 4.17.12-alt1
- Update to security release of Samba 4.17
- Security fixes (Samba#15422, Samba#15424, Samba#15439, Samba#15473, Samba#15474):
 + CVE-2023-3961:  Unsanitized pipe names allow SMB clients to connect as root
                   to existing unix domain sockets on the file system.
                   https://www.samba.org/samba/security/CVE-2023-3961.html

 + CVE-2023-4091:  SMB client can truncate files to 0 bytes by opening files
                   with OVERWRITE disposition when using the acl_xattr Samba VFS
                   module with the smb.conf setting
                   "acl_xattr:ignore system acls = yes"
                   https://www.samba.org/samba/security/CVE-2023-4091.html

 + CVE-2023-4154:  An RODC and a user with the GET_CHANGES right can view all
                   attributes, including secrets and passwords.  Additionally,
                   the access check fails open on error conditions.
                   https://www.samba.org/samba/security/CVE-2023-4154.html

 + CVE-2023-42669: Calls to the rpcecho server on the AD DC can request that the
                   server block for a user-defined amount of time, denying
                   service.
                   https://www.samba.org/samba/security/CVE-2023-42669.html

 + CVE-2023-42670: Samba can be made to start multiple incompatible RPC
                   listeners, disrupting service on the AD DC.
                   https://www.samba.org/samba/security/CVE-2023-42670.html
Oct. 7, 2023 Evgeny Sinelnikov 4.17.11-alt2
- New build scheme with separate upstream, altlinux and sisyphus branches.
Sept. 23, 2023 Evgeny Sinelnikov 4.17.11-alt1
- Update to security release of Samba 4.17
- smbd fileserver fixes (Samba#15419, Samba#15420, Samba#15430, Samba#15432,
                         Samba#15417, Samba#15346, Samba#15453, Samba#15435):
  + Weird filename can cause assert to fail in openat_pathref_fsp_nosymlink().
  + reply_sesssetup_and_X() can dereference uninitialized tmp pointer.
  + Missing return in reply_exit_done().
  + TREE_CONNECT without SETUP causes smbd to use uninitialized pointer.
  + Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted
    to remove the destination.
  + 2-3min delays at reconnect with smb2_validate_sequence_number:
    bad message_id 2.
  + File doesn't show when user doesn't have permission if
    aio_pthread is loaded.
  + Regression DFS not working with widelinks = true.

- replication fixes (Samba#15401, Samba#15407)
  + Improve GetNChanges to address some (but not all "Azure AD Connect")
    syncronisation tool looping during the initial user sync phase.
  + Samba replication logs show (null) DN.

- tools fixes (Samba#15384, Samba#15441, Samba#15451):
  + net ads lookup (with unspecified realm) fails
  + samba-tool ntacl get segfault if aio_pthread appended.
  + ctdb_killtcp fails to work with --enable-pcap and libpcap >= 1.9.1.

- other protocol fixes (Samba#15446, Samba#9959, Samba#15463
                        Samba#15449, Samba#15342, Samba#15427):
  + DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed.
  + Windows client join fails if a second container CN=System exists somewhere.
  + macOS mdfind returns only 50 results.
  + mdssvc: Do an early talloc_free() in _mdssvc_open().
  + Spotlight sometimes returns no results on latest macOS.
  + Spotlight results return wrong date in result list.

- Compatibility fixes of spec (thx asheplyakov@):
  + added missing BR: alternatives.
  + added rpm-macros-alterinatives as a pre-requirement.
  + added missing build-requirements: flex, liblmdb-devel.
  + dropped obsolete build dependency on gtk+2.
  + samba-client: libldb-cmdline-samba4.so.

- Disabled tracker backend in spotlight (obsolete with version less than 3.x).
- Disabled glusterfs on armh due it not supported on this architecture.