-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 22 May 2026 09:40:47 +0300 Source: samba Binary: samba-ad-dc samba-ad-provision samba-common Architecture: all Version: 2:4.17.12+dfsg-0+deb12u4 Distribution: bookworm-security Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Michael Tokarev Description: samba-ad-dc - Samba control files to run AD Domain Controller samba-ad-provision - Samba files needed for AD domain provision samba-common - common files used by both the Samba server and client Changes: samba (2:4.17.12+dfsg-0+deb12u4) bookworm-security; urgency=medium . * https://bugzilla.samba.org/show_bug.cgi?id=16018 May-2026 samba security update fixing the following issues: CVE-2026-2340: vfs_worm does not block directory modification https://bugzilla.samba.org/show_bug.cgi?id=15997 CVE-2026-3012: group policy certificate enrollment uses http:// without validation https://bugzilla.samba.org/show_bug.cgi?id=16003 CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server https://bugzilla.samba.org/show_bug.cgi?id=16012 CVE-2026-4480: Unauthenticated Remote Code Execution using print command https://bugzilla.samba.org/show_bug.cgi?id=16033 CVE-2026-4408: Remote Code Execution in SAMR when check password script contains %u substitution placeholder https://bugzilla.samba.org/show_bug.cgi?id=16034 Checksums-Sha1: 2164f14aeec3359e45ae4fbbb36cc105340156a8 30688 samba-ad-dc_4.17.12+dfsg-0+deb12u4_all.deb 1190fe4afedc8123261e686c470a39a916f73cf0 415968 samba-ad-provision_4.17.12+dfsg-0+deb12u4_all.deb a509f1e07b94bf2910d067c0bcd2bc9f0800c60e 88684 samba-common_4.17.12+dfsg-0+deb12u4_all.deb 50038563da101cda8b61031c3e2032e360a93b09 6643 samba_4.17.12+dfsg-0+deb12u4_all-buildd.buildinfo Checksums-Sha256: 49decdb561d956741dfea56682b5ac797caeee1f51798f31e1173ada7cfc9746 30688 samba-ad-dc_4.17.12+dfsg-0+deb12u4_all.deb e9e8005f19d3fde03f41a5c5f13b21bc7568a26265b55c40d51a838f0011283d 415968 samba-ad-provision_4.17.12+dfsg-0+deb12u4_all.deb 4c0c1a540b0bc8b69af47c7e98d5a6788d624d36b75ae8e98ae1bbc79131128b 88684 samba-common_4.17.12+dfsg-0+deb12u4_all.deb dab1bcdd2e3809c0526b6353df6b93b97035250f447186aa62fb13200fcc3cab 6643 samba_4.17.12+dfsg-0+deb12u4_all-buildd.buildinfo Files: addaead8f0f64cf766ff70bd24991194 30688 net optional samba-ad-dc_4.17.12+dfsg-0+deb12u4_all.deb 60986a5fb103d365bea8665c5c22db75 415968 net optional samba-ad-provision_4.17.12+dfsg-0+deb12u4_all.deb f598023e1d4515173adf31c02f4eb92d 88684 net optional samba-common_4.17.12+dfsg-0+deb12u4_all.deb e2d3c2ac09ce4bf8fba80c874c5cc777 6643 net optional samba_4.17.12+dfsg-0+deb12u4_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmoQALAACgkQN8Ugyu9d QiRMThAAtW41h2gm9p7gcCORXYsJ0jJvJha4kPcFFcjXowfnbu24rnmeVT05MFHS 0lB+0oP/KzidSXcXL2tUylAK4brLy0S0nNgkg9zUHXstai/AJeKxo6to0i352QFy F2oQvauGJ0auHNcuoQFXYtOqbBmsb8Gbpnwh9QrkoUK6IPCKnfYHFp0QT6mf1B0b GXSnPhWIaaPzQj8l2Z2dhj94vtByAqLU/Ct18erthu4eGaYac2z1cC09RfLDfbIB lY6flzBWJnPmujfLljnvEAyfKk1el7skb5eIpgrPzcvHa+OI1WZ5bDSR8AI0aqF+ h5kPVJRoSTs7SG9pGb+UHwxkYPmi02pvLFe2S/HB6ppmByxemG4MRdCLdUYP5R+n dbSNimzWTKhpnDhs/ZnWpjvPJhRhOWbblo/c9oRNnZgAfp5b+n3PIXBSZrvkOh7X NTwFM09vKgTiwndPgLFgRMj3dwe7TyDiHvy7tsSyESipsvD6mtqTiOZHpajWUcdY 0TtViiYzDwoMke1Ow2u256r/qMcGZIBtV1Xd5hD6DCobi/bgKuQFLmUIstxpI9fm jqYeP1o8pk7dJRqFqRPqq76mJCokc+lfz8VIzA5FWZaFtZBLQSlzQLkT5YWZL7C2 CpKKnaxp7y02clJ36zfy2HO2uAVmFG9Mc5VkQTJO9nqodkRWaeo= =bvUa -----END PGP SIGNATURE-----