Package samba: Information

  • Default inline alert: Version in the repository: 4.20.1-alt2

Source package: samba
Version: 4.17.11-alt2
Latest version according to Repology
Build time:  Oct 18, 2023, 07:58 AM in the task #331153
Category: System/Servers
Report package bug
License: GPLv3+ and LGPLv3+
Summary: The Samba4 CIFS and AD client and server suite
Description: 
Samba is the standard Windows interoperability suite of programs for Linux and Unix.

List of rpms provided by this srpm:
admx-samba (noarch)
libldb-modules-ldap (x86_64, ppc64le, i586, armh, aarch64)
libldb-modules-ldap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient-devel (x86_64, ppc64le, i586, armh, aarch64)
libwbclient (x86_64, ppc64le, i586, armh, aarch64)
libwbclient-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libwbclient-devel (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba-devel (x86_64, ppc64le, i586, armh, aarch64)
samba (x86_64, ppc64le, i586, armh, aarch64)
samba-client (x86_64, ppc64le, i586, armh, aarch64)
samba-client-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-common (noarch)
samba-common-client (noarch)
samba-common-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-common-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-common-tools (x86_64, ppc64le, i586, armh, aarch64)
samba-common-tools-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-ctdb (x86_64, ppc64le, i586, armh, aarch64)
samba-ctdb-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dc (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-client (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-common (noarch)
samba-dc-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-mitkrb5 (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-mitkrb5-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dcerpc (x86_64, ppc64le, i586, armh, aarch64)
samba-dcerpc-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-devel (x86_64, ppc64le, i586, armh, aarch64)
samba-doc (noarch)
samba-gpupdate (x86_64, ppc64le, i586, armh, aarch64)
samba-krb5-printing (x86_64, ppc64le, i586, armh, aarch64)
samba-krb5-printing-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-pidl (noarch)
samba-test (x86_64, ppc64le, i586, armh, aarch64)
samba-test-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-usershares (x86_64, ppc64le, i586, armh, aarch64)
samba-util-private-headers (x86_64, ppc64le, i586, armh, aarch64)
samba-vfs-cephfs (x86_64, ppc64le, aarch64)
samba-vfs-cephfs-debuginfo (x86_64, ppc64le, aarch64)
samba-vfs-glusterfs (x86_64, ppc64le, i586, aarch64)
samba-vfs-glusterfs-debuginfo (x86_64, ppc64le, i586, aarch64)
samba-vfs-snapper (x86_64, ppc64le, i586, armh, aarch64)
samba-vfs-snapper-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-clients (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-clients-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-common (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-localauth (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-localauth-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-locator (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-locator-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
task-samba-dc (noarch)
task-samba-dc-mitkrb5 (noarch)

Maintainer: Evgeny Sinelnikov



    1. libpam-devel
    2. netpbm
    3. ceph-devel
    4. libpopt-devel
    5. python3-devel
    6. python3-module-dns
    7. python3-module-markdown
    8. dblatex
    9. /proc
    10. python3-module-pyldb-devel
    11. /usr/bin/rpcgen
    12. libcap-devel
    13. python3-module-talloc-devel
    14. python3-module-tdb
    15. python3-module-tevent
    16. libcups-devel
    17. docbook-style-xsl
    18. libreadline-devel
    19. libdbus-devel
    20. glibc-devel
    21. glibc-kernheaders
    22. libe2fs-devel
    23. html2text
    24. libssl-devel
    25. flex
    26. admx-lint
    27. gawk
    28. alternatives
    29. rpm-build-python3
    30. libglusterfs-api-devel
    31. rpm-macros-alternatives
    32. libgnutls-devel
    33. libgpgme-devel
    34. perl-JSON
    35. libsystemd-devel
    36. perl-Parse-Yapp
    37. libtalloc-devel >= 2.3.4
    38. libiniparser-devel
    39. libacl-devel
    40. libtasn1-devel
    41. libtasn1-utils
    42. perl-devel
    43. libarchive-devel >= 3.1.2
    44. libjansson-devel
    45. libtdb-devel >= 1.4.7
    46. libattr-devel
    47. libavahi-devel
    48. libtevent-devel >= 0.13.0
    49. krb5-kdc
    50. libtirpc-devel
    51. libuuid-devel
    52. libkrb5-devel
    53. libldap-devel
    54. libldb-devel = 2.6.2
    55. libxslt
    56. libncurses-devel
    57. liblmdb-devel >= 0.9.16
    58. xsltproc
    59. zlib-devel

Last changed


Oct. 7, 2023 Evgeny Sinelnikov 4.17.11-alt2
- New build scheme with separate upstream, altlinux and sisyphus branches.
Sept. 23, 2023 Evgeny Sinelnikov 4.17.11-alt1
- Update to security release of Samba 4.17
- smbd fileserver fixes (Samba#15419, Samba#15420, Samba#15430, Samba#15432,
                         Samba#15417, Samba#15346, Samba#15453, Samba#15435):
  + Weird filename can cause assert to fail in openat_pathref_fsp_nosymlink().
  + reply_sesssetup_and_X() can dereference uninitialized tmp pointer.
  + Missing return in reply_exit_done().
  + TREE_CONNECT without SETUP causes smbd to use uninitialized pointer.
  + Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted
    to remove the destination.
  + 2-3min delays at reconnect with smb2_validate_sequence_number:
    bad message_id 2.
  + File doesn't show when user doesn't have permission if
    aio_pthread is loaded.
  + Regression DFS not working with widelinks = true.

- replication fixes (Samba#15401, Samba#15407)
  + Improve GetNChanges to address some (but not all "Azure AD Connect")
    syncronisation tool looping during the initial user sync phase.
  + Samba replication logs show (null) DN.

- tools fixes (Samba#15384, Samba#15441, Samba#15451):
  + net ads lookup (with unspecified realm) fails
  + samba-tool ntacl get segfault if aio_pthread appended.
  + ctdb_killtcp fails to work with --enable-pcap and libpcap >= 1.9.1.

- other protocol fixes (Samba#15446, Samba#9959, Samba#15463
                        Samba#15449, Samba#15342, Samba#15427):
  + DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed.
  + Windows client join fails if a second container CN=System exists somewhere.
  + macOS mdfind returns only 50 results.
  + mdssvc: Do an early talloc_free() in _mdssvc_open().
  + Spotlight sometimes returns no results on latest macOS.
  + Spotlight results return wrong date in result list.

- Compatibility fixes of spec (thx asheplyakov@):
  + added missing BR: alternatives.
  + added rpm-macros-alterinatives as a pre-requirement.
  + added missing build-requirements: flex, liblmdb-devel.
  + dropped obsolete build dependency on gtk+2.
  + samba-client: libldb-cmdline-samba4.so.

- Disabled tracker backend in spotlight (obsolete with version less than 3.x).
- Disabled glusterfs on armh due it not supported on this architecture.
July 23, 2023 Evgeny Sinelnikov 4.17.10-alt1
- Update to maintenance release of Samba 4.17:
  + Secure channel faulty since Windows 10/11 update 07/2023 (KB5028166).

- Security fixes (Samba#15418):
  + CVE-2022-2127:  When winbind is used for NTLM authentication, a maliciously
                    crafted request can trigger an out-of-bounds read in winbind
                    and possibly crash it.
                    https://www.samba.org/samba/security/CVE-2022-2127.html

  + CVE-2023-3347:  SMB2 packet signing is not enforced if an admin configured
                    "server signing = required" or for SMB2 connections to Domain
                    Controllers where SMB2 packet signing is mandatory.
                    https://www.samba.org/samba/security/CVE-2023-3347.html

  + CVE-2023-34966: An infinite loop bug in Samba's mdssvc RPC service for
                    Spotlight can be triggered by an unauthenticated attacker by
                    issuing a malformed RPC request.
                    https://www.samba.org/samba/security/CVE-2023-34966.html

  + CVE-2023-34967: Missing type validation in Samba's mdssvc RPC service for
                    Spotlight can be used by an unauthenticated attacker to
                    trigger a process crash in a shared RPC mdssvc worker process.
                    https://www.samba.org/samba/security/CVE-2023-34967.html

  + CVE-2023-34968: As part of the Spotlight protocol Samba discloses the server-
                    side absolute path of shares and files and directories in
                    search results.
                    https://www.samba.org/samba/security/CVE-2023-34968.html