Release date:
2026-05-05 01:46:44 UTC
Description:
* SECURITY UPDATE: domain user can become root on a domain member by
renaming a machine account
- debian/patches/CVE-2020-25717.patch: backport the el6/ol6 8-commit
subset (samba 3.6.23 precedent); introduce the new "min domain
uid" smb.conf parameter (default 1000) and enforce it in
check_account() so a domain logon resolving to a uid below the
threshold is rejected with NT_STATUS_INVALID_TOKEN, drop the
DOMAIN\user to user prefix-stripping fallback in smb_getpwnam(),
stop autocreating local users from check_account() and from the
kerberos guest fallback by passing create=false, drop the
!winbind_ping() branch in create_local_token() so a missing
winbindd no longer silently switches the unix-token computation,
and require a PAC in any domain mode (DC or member) inside
gensec_generate_session_info_pac() returning
NT_STATUS_NO_IMPERSONATION_TOKEN otherwise (the gensec hunk is the
jointly tagged CVE-2020-25717+CVE-2020-25719 commit, so this
update also delivers the member-server portion of CVE-2020-25719;
the DC-side portion of CVE-2020-25719 is tracked separately under
ELSCVE-104393)
- CVE-2020-25717
* SECURITY UPDATE: privileged attribute escalation and structural
objectclass change in active directory ldap server
- debian/patches/CVE-2020-25722.patch: in
source4/dsdb/samdb/ldb_modules/objectclass.c, capture the current
structural objectclass at the start of objectclass_do_mod and
reject any modify that would change it; in
source4/dsdb/samdb/ldb_modules/samldb.c, factor the domain
ntSecurityDescriptor lookup into samldb_get_domain_secdesc() and
add samldb_check_sensitive_attributes() invoked from samldb_add()
and samldb_modify() to refuse non-system writes to sidHistory,
gate msDS-SecondaryKrbTgtNumber on the DS-Install-Replica
extended right, and gate msDS-AllowedToDelegateTo on
SePrivEnableDelegation
- CVE-2020-25722
Updated packages:
-
ctdb_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:9489df285943770d7f0c976a11d219c27dc99cd6
-
libnss-winbind_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:db541586aa9629e0ce45d77196ff80980d614a9a
-
libpam-winbind_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:8c2dee8934f82fa734d71f8665ad3bb90258f8f0
-
libparse-pidl-perl_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:ef64938e8d1b127469fe1c3e8f9670c6d3f10627
-
libsmbclient_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:5710090efe067155b069d2ce009105506ea7d433
-
libsmbclient-dev_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:009745c95eadf42b40a8057bbc1f018035b51e5a
-
libwbclient-dev_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:4b6054e9a7874b44c940e2125be91cd0671234de
-
libwbclient0_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:bd3864652227ecc30461ee452b0cb192ea4f1d0d
-
python-samba_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:68281619b857f4a0fc6adda7ce850b65a6240f38
-
registry-tools_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:cecac10e6e207b839e1d002edb7e3378e193b095
-
samba_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:18880619b55b42593025a1ff20023429878ea6fd
-
samba-common_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_all.deb
sha:93a4a969525456986b9d93d739c8e83913b5bdd1
-
samba-common-bin_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:d436955d335a8a5131d741599f2724c5be386e03
-
samba-dev_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:3e5b5bca9f459a1f346dddeae767bc3972c90187
-
samba-dsdb-modules_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:4da42d4d6937476b576773fe298bb1a591d1a693
-
samba-libs_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:f028941cea3b0cc05b5ec4ef456141b3aaca75d2
-
samba-testsuite_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:01d351076b84deaada557fa5adc6d79faa12eca2
-
samba-vfs-modules_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:011ff90f2c76fde39e6db6f569f25f81493d3666
-
smbclient_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:5132d5073a0a1ccea79490c5cff36add9187fba4
-
winbind_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
sha:7ddf10d1a19aad4f3df1cb54df3b60d53222c31c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.