Commit graph

151 commits

Author SHA1 Message Date
Christian Hewitt
815cd5cbbf
Merge pull request #7828 from mglae/le11_samba_config
samba: samba-config: operate atomic and support any user name and password
2023-11-03 12:23:35 +04:00
Rudi Heitbaum
92601ec584 samba: update to 4.17.12
ref:
- https://www.samba.org/samba/history/samba-4.17.12.html
2023-10-11 12:45:50 +00:00
Rudi Heitbaum
b5fc6bd727 samba: update to 4.17.11
Release notes:
- https://www.samba.org/samba/history/samba-4.17.11.html
2023-09-07 09:46:09 +00:00
Rudi Heitbaum
5e45a8df12 samba: update to 4.17.10
Release notes:
- https://www.samba.org/samba/history/samba-4.7.10.html
2023-07-20 11:19:50 +00:00
Rudi Heitbaum
b3075207e7 samba: update to 4.17.9
Changes since 4.17.8
--------------------

o  Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
   * BUG 15404: Backport --pidl-developer fixes.

o  Ralph Boehme <slow@samba.org>
   * BUG 15275: smbd_scavenger crashes when service smbd is stopped.
   * BUG 15378: vfs_fruit might cause a failing open for delete.

o  Samuel Cabrero <scabrero@samba.org>
   * BUG 14030: named crashes on DLZ zone update.

o  Volker Lendecke <vl@samba.org>
   * BUG 15361: winbind recurses into itself via rpcd_lsad.
   * BUG 15382: cli_list loops 100% CPU against pre-lanman2 servers.
   * BUG 15391: smbclient leaks fds with showacls.

o  Stefan Metzmacher <metze@samba.org>
   * BUG 15374: aes256 smb3 encryption algorithms are not allowed in
     smb3_sid_parse().
   * BUG 15413: winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR.

o  Jones Syue <jonessyue@qnap.com>
   * BUG 15403: smbget memory leak if failed to download files recursively.
2023-07-07 10:21:25 +00:00
Rudi Heitbaum
78e2ec014a samba: update to 4.17.8
ann:
- https://lists.samba.org/archive/samba-announce/2023/000635.html
2023-05-11 09:37:04 +00:00
mglae
8546c5a9aa samba: include smbd-config in samba-config
smbd-config is only used from samba-config and therefore deleted.

/run/samba/smb.conf is created in a single step via temp file
2023-05-11 00:21:10 +02:00
Rudi Heitbaum
c44ef45e99 samba: update to 4.17.7
release notes:
- https://www.samba.org/samba/history/samba-4.17.6.html
- https://www.samba.org/samba/history/samba-4.17.7.html
2023-03-29 15:39:44 +00:00
Rudi Heitbaum
fc04ada49e samba: update to 4.17.5
release notes:
- https://www.samba.org/samba/history/samba-4.17.5.html
2023-01-27 07:27:04 +00:00
Rudi Heitbaum
6a997dbe82 samba: update to 4.17.4
release notes:
- https://www.samba.org/samba/history/samba-4.17.4.html
2022-12-16 07:43:14 +00:00
Rudi Heitbaum
55e4dd83a8 samba: update to 4.17.3
release notes:
- https://www.samba.org/samba/history/samba-4.17.3.html
2022-11-15 21:02:23 +00:00
Rudi Heitbaum
39178c8997 samba: update to 4.17.2 2022-10-27 07:21:16 +00:00
Rudi Heitbaum
66687a0ce0 samba: update to 4.17.1
release notes:
- https://www.samba.org/samba/history/samba-4.17.1.html
2022-10-19 12:48:56 +00:00
SupervisedThinking
611b07c484 various: link with gold if supported 2022-09-22 18:27:07 +02:00
Rudi Heitbaum
a3eff3c574 samba: update to 4.17.0
wiki:
- https://wiki.samba.org/index.php/Release_Planning_for_Samba_4.17

release notes:
- https://www.samba.org/samba/history/samba-4.17.0.html
2022-09-14 13:35:32 +00:00
Rudi Heitbaum
5f44b65536 samba: update to 4.16.5
release notes:
- https://www.samba.org/samba/history/samba-4.16.5.html
2022-09-08 11:20:24 +00:00
Rudi Heitbaum
7a747bb373 samba: fix dcerpc and srvsvc browsing 2022-08-31 16:34:22 +00:00
Rudi Heitbaum
0285c5648e samba: update to 4.16.4
ann:
- https://lists.samba.org/archive/samba/2022-July/241442.html
release notes:
- https://www.samba.org/samba/history/samba-4.16.4.html
2022-07-27 10:26:39 +00:00
Rudi Heitbaum
d0073a1904 samba: update to 4.16.3 2022-07-19 04:28:34 +00:00
Rudi Heitbaum
8a4698bb64 samba: update to 4.16.2
changelog:
- https://www.samba.org/samba/history/samba-4.16.1.html
- https://www.samba.org/samba/history/samba-4.16.2.html
2022-06-13 08:29:11 +00:00
Rudi Heitbaum
ab5e1ad81b samba: upstream build fix for 4.16.0
drop the workaround patch and include the upstream patch.

adjust the package.mk file to call make not waf directly as specified by
samba. This sets the PYTHONHASHSEED hash randomization to a static value
of 1, thus having reproducable (non random) ordering iteration of values
in variables.

https://bugzilla.samba.org/show_bug.cgi?id=15033
2022-06-13 08:28:23 +00:00
heitbaum
e5830dc584 samba: update to 4.16.0
release notes:
- https://www.samba.org/samba/history/samba-4.16.0.html

Please review:
- Heimdal-8.0pre used for Samba Internal Kerberos, adds FAST support
2022-03-22 07:35:26 +00:00
heitbaum
b43721da58 samba: update to 4.13.17
release notes:
- https://www.samba.org/samba/history/samba-4.13.17.html

                   ===============================
                   Release Notes for Samba 4.13.17
                          January 31, 2022
                   ===============================

This is a security release in order to address the following defects:

o CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module.
                  https://www.samba.org/samba/security/CVE-2021-44142.html

o CVE-2022-0336:  Re-adding an SPN skips subsequent SPN conflict checks.
                  https://www.samba.org/samba/security/CVE-2022-0336.html

Changes since 4.13.16
---------------------

o  Ralph Boehme <slow@samba.org>
   * BUG 14914: CVE-2021-44142

o  Joseph Sutton <josephsutton@catalyst.net.nz>
   * BUG 14950: CVE-2022-0336
2022-02-01 10:32:45 +00:00
heitbaum
e49d784342 samba: update to 4.13.16
update 4.13.15 (2021-12-15) to 4.13.16 (2022-01-10)

release notes:
- https://www.samba.org/samba/history/samba-4.13.16.html
- https://www.samba.org/samba/security/CVE-2021-43566.html
2022-01-12 10:39:53 +00:00
heitbaum
ec45ff05c6 samba: update to 4.13.15
release notes:
- https://www.samba.org/samba/history/samba-4.13.15.html
2021-12-28 10:23:58 +00:00
heitbaum
c2d6efc729 samba: add libunwind as a target dependency 2021-12-05 08:30:21 +00:00
heitbaum
7af3568bd9 samba: update to 4.13.14
update 4.13.13 (2021-10-29) to 4.13.14 (2021-11-09)

release notes: https://www.samba.org/samba/history/samba-4.13.14.html

                   ===============================
                   Release Notes for Samba 4.13.14
                           November 9, 2021
                   ===============================

This is a security release in order to address the following defects:

o CVE-2016-2124:  SMB1 client connections can be downgraded to plaintext
                  authentication.
                  https://www.samba.org/samba/security/CVE-2016-2124.html

o CVE-2020-25717: A user on the domain can become root on domain members.
                  https://www.samba.org/samba/security/CVE-2020-25717.html
                  (PLEASE READ! There are important behaviour changes described)

o CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued
                  by an RODC.
                  https://www.samba.org/samba/security/CVE-2020-25718.html

o CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos
                  tickets.
                  https://www.samba.org/samba/security/CVE-2020-25719.html

o CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers
                  (eg objectSid).
                  https://www.samba.org/samba/security/CVE-2020-25721.html

o CVE-2020-25722: Samba AD DC did not do suffienct access and conformance
                  checking of data stored.
                  https://www.samba.org/samba/security/CVE-2020-25722.html

o CVE-2021-3738:  Use after free in Samba AD DC RPC server.
                  https://www.samba.org/samba/security/CVE-2021-3738.html

o CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability.
                  https://www.samba.org/samba/security/CVE-2021-23192.html

Changes since 4.13.13
---------------------

o  Douglas Bagnall &lt;douglas.bagnall@catalyst.net.nz&gt;
   * CVE-2020-25722

o  Andrew Bartlett &lt;abartlet@samba.org&gt;
   * CVE-2020-25718
   * CVE-2020-25719
   * CVE-2020-25721
   * CVE-2020-25722

o  Ralph Boehme &lt;slow@samba.org&gt;
   * CVE-2020-25717

o  Alexander Bokovoy &lt;ab@samba.org&gt;
   * CVE-2020-25717

o  Samuel Cabrero &lt;scabrero@samba.org&gt;
   * CVE-2020-25717

o  Nadezhda Ivanova &lt;nivanova@symas.com&gt;
   * CVE-2020-25722

o  Stefan Metzmacher &lt;metze@samba.org&gt;
   * CVE-2016-2124
   * CVE-2020-25717
   * CVE-2020-25719
   * CVE-2020-25722
   * CVE-2021-23192
   * CVE-2021-3738
   * ldb: version 2.2.3

o  Andreas Schneider &lt;asn@samba.org&gt;
   * CVE-2020-25719

o  Joseph Sutton &lt;josephsutton@catalyst.net.nz&gt;
   * CVE-2020-17049
   * CVE-2020-25718
   * CVE-2020-25719
   * CVE-2020-25721
   * CVE-2020-25722
   * MS CVE-2020-17049
2021-11-10 18:52:34 +11:00
heitbaum
4be46be119 samba: update to 4.13.13
update 4.13.12 (2021-09-22) to 4.13.13 (2021-10-29)

release notes:
- https://www.samba.org/samba/history/samba-4.13.13.html

Changes since 4.13.12
---------------------

o  Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
   * BUG 14868: rodc_rwdc test flaps.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Andrew Bartlett <abartlet@samba.org>
   * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
     bit' S4U2Proxy Constrained Delegation bypass in Samba with
     embedded Heimdal.
   * BUG 14836: Python ldb.msg_diff() memory handling failure.
   * BUG 14845: "in" operator on ldb.Message is case sensitive.
   * BUG 14848: Release LDB 2.3.1 for Samba 4.14.9.
   * BUG 14871: Fix Samba support for UF_NO_AUTH_DATA_REQUIRED.
   * BUG 14874: Allow special chars like "@" in samAccountName when generating
     the salt.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Isaac Boukris <iboukris@gmail.com>
   * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
     bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Viktor Dukhovni <viktor@twosigma.com>
   * BUG 12998: Fix transit path validation.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Luke Howard <lukeh@padl.com>
   * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
     bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Stefan Metzmacher <metze@samba.org>
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  David Mulder <dmulder@suse.com>
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Andreas Schneider <asn@samba.org>
   * BUG 14870: Prepare to operate with MIT krb5 >= 1.20.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Joseph Sutton <josephsutton@catalyst.net.nz>
   * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
     bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal.
   * BUG 14645: rpcclient NetFileEnum and net rpc file both cause lock order
     violation: brlock.tdb, share_entries.tdb.
   * BUG 14836: Python ldb.msg_diff() memory handling failure.
   * BUG 14845: "in" operator on ldb.Message is case sensitive.
   * BUG 14848: Release LDB 2.3.1 for Samba 4.14.9.
   * BUG 14868: rodc_rwdc test flaps.
   * BUG 14871: Fix Samba support for UF_NO_AUTH_DATA_REQUIRED.
   * BUG 14874: Allow special chars like "@" in samAccountName when generating
     the salt.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.

o  Nicolas Williams <nico@twosigma.com>
   * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze
     bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal.
   * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.
2021-10-30 13:02:27 +11:00
mglae
d38aac52a4 wsdd2: initial package v1.8.6 2021-10-26 18:29:51 +02:00
heitbaum
5cf5025376 samba: update to 4.13.12
release notes:
- https://www.samba.org/samba/history/samba-4.13.12.html
2021-10-02 22:17:12 +10:00
heitbaum
80523c6a1c samba: update to 4.13.11
update 4.13.9 to 4.13.11

release notes:
- https://www.samba.org/samba/history/samba-4.13.10.html
- https://www.samba.org/samba/history/samba-4.13.11.html
2021-09-07 22:04:37 +10:00
heitbaum
111da88831 samba: update to 4.13.9
update 4.13.8 (2021-04-29) to 4.13.9 (2021-05-11)
release notes: https://www.samba.org/samba/history/samba-4.13.9.html

This is the latest stable release of the Samba 4.13 release series.

Changes since 4.13.8
--------------------

o  Jeremy Allison <jra@samba.org>
   * BUG 14696: s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success.

o  Andrew Bartlett <abartlet@samba.org>
   * BUG 14689: Add documentation for dsdb_group_audit and dsdb_group_json_audit
     to "log level", synchronise "log level" in smb.conf with the code.

o  Ralph Boehme <slow@samba.org>
   * BUG 14672: Fix smbd panic when two clients open same file.
   * BUG 14675: Fix memory leak in the RPC server.
   * BUG 14679: s3: smbd: Fix deferred renames.

o  Samuel Cabrero <scabrero@samba.org>
   * BUG 14675: s3-iremotewinspool: Set the per-request memory context.

o  Volker Lendecke <vl@samba.org>
   * BUG 14675: rpc_server3: Fix a memleak for internal pipes.

o  Stefan Metzmacher <metze@samba.org>
   * BUG 11899: third_party: Update socket_wrapper to version 1.3.2.
   * BUG 14640: third_party: Update socket_wrapper to version 1.3.3.

o  Christof Schmitt <cs@samba.org>
   * BUG 14663: idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid
     conflict.

o  Martin Schwenke <martin@meltin.net
   * BUG 14288: Fix the build on OmniOS.
2021-05-13 09:55:14 +00:00
heitbaum
4c499faaf0 samba: update to 4.13.8
update 4.1.7 (2021-03-24) to 4.18.8 (2021-04-29)
release notes: https://www.samba.org/samba/history/samba-4.13.8.html

==

This is a security release in order to address the following defect:

o CVE-2021-20254: Negative idmap cache entries can cause incorrect group entries
  in the Samba file server process token.

=======
Details
=======

o  CVE-2021-20254:
   The Samba smbd file server must map Windows group identities (SIDs) into unix
   group ids (gids). The code that performs this had a flaw that could allow it
   to read data beyond the end of the array in the case where a negative cache
   entry had been added to the mapping cache. This could cause the calling code
   to return those values into the process token that stores the group
   membership for a user.

   Most commonly this flaw caused the calling code to crash, but an alert user
   (Peter Eriksson, IT Department, Linköping University) found this flaw by
   noticing an unprivileged user was able to delete a file within a network
   share that they should have been disallowed access to.

   Analysis of the code paths has not allowed us to discover a way for a
   remote user to be able to trigger this flaw reproducibly or on demand,
   but this CVE has been issued out of an abundance of caution.

Changes since 4.13.7
--------------------

o  Volker Lendecke <vl@samba.org>
   * BUG 14571: CVE-2021-20254: Fix buffer overrun in sids_to_unixids().
2021-04-30 10:19:04 +00:00
heitbaum
2ca6482365 samba: update to 4.13.7
update 4.13.5 to 4.13.7
changelog:
- https://www.samba.org/samba/history/samba-4.13.6.html
- https://www.samba.org/samba/history/samba-4.13.7.html
2021-03-25 08:47:57 +00:00
heitbaum
7f82a9c80f samba: update to 4.13.5
update 4.13.4 to 4.13.5
changelog: https://www.samba.org/samba/history/samba-4.13.5.html
2021-03-10 07:51:46 +00:00
heitbaum
87fe8d153e samba: update to 4.13.4
update 4.13.3 to 4.13.4
changelog: https://www.samba.org/samba/history/samba-4.13.4.html
2021-01-26 11:38:45 +00:00
Ian Leonard
3baf91e87d network: automated code cleanup
Signed-off-by: Ian Leonard <antonlacon@gmail.com>
2021-01-19 19:34:12 +00:00
heitbaum
e02b3d827d samba: update to 4.13.3 2020-12-16 12:54:29 +00:00
heitbaum
08de029928 samba: update to current stable 4.13.2 2020-12-05 11:24:17 +00:00
Ian Leonard
cf05a65c32 samba: update to 4.12.7
Signed-off-by: Ian Leonard <antonlacon@gmail.com>
2020-10-15 05:51:00 +00:00
Ian Leonard
f53ee20b56 samba: update to 4.12.5
Signed-off-by: Ian Leonard <antonlacon@gmail.com>
2020-07-14 17:09:26 +00:00
Christian Hewitt
76f835fc9d
Merge pull request #4445 from antonlacon/le10-june-updates
June package updates
2020-07-14 17:52:51 +04:00
CvH
f89b9153d8 samba: disable automatic icu pickup
if you build icu before samba, icu gets used at buildtime and fails
2020-06-28 21:46:05 +02:00
Ian Leonard
97d0dc34f1 samba: update to 4.12.3
Signed-off-by: Ian Leonard <antonlacon@gmail.com>
2020-06-22 16:05:53 +00:00
MilhouseVH
5161dd6e0d samba: update to samba-4.12.2 2020-04-28 10:38:42 +01:00
MilhouseVH
1e40cb6f7f samba: update to samba-4.12.1 2020-04-07 11:57:24 +01:00
MilhouseVH
79a201455e samba: update to samba-4.12.0 2020-03-03 12:20:23 +00:00
MilhouseVH
8a0f281712 samba: update to samba-4.11.6 2020-01-28 10:33:01 +00:00
MilhouseVH
ef2dc90b60 samba: update to samba-4.11.5 2020-01-21 14:57:15 +00:00
MilhouseVH
36f6cb5f8d samba: update to samba-4.11.4 2019-12-16 15:38:23 +00:00