Bug 15929 - October 2025 security release tracking bug
Summary: October 2025 security release tracking bug
Status: RESOLVED FIXED
Alias: None
Product: Samba 4.1 and newer
Classification: Unclassified
Component: Other (show other bugs)
Version: unspecified
Hardware: All All
: P5 normal (vote)
Target Milestone: ---
Assignee: Jule Anger
QA Contact: Samba QA Contact
URL:
Keywords:
Depends on: CVE-2025-9640 CVE-2025-10230
Blocks:
  Show dependency treegraph
 
Reported: 2025-10-06 08:25 UTC by Douglas Bagnall
Modified: 2025-10-21 20:58 UTC (History)
1 user (show)

See Also:


Attachments
Combined patch for 4.17 (22.06 KB, patch)
2025-10-06 08:35 UTC, Douglas Bagnall
gary: review+
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Douglas Bagnall 2025-10-06 08:25:58 UTC
There will be a security release on October 15, 2025.

In a few days we will be pre-announcing it a bit like this:

This is a heads-up that there will be Samba security updates for 4.21, 4.22, and 4.23 on Wednesday, October 15, 2025. Please make sure that your Samba servers will be updated soon after the release!

Impacted component:
 - AD DC (CVSS 10, High, when using a very unusual configuration)
 - File services (CVSS 4.3, Low, in a relatively widespread configuration)

The AD DC bug will affect very few, possibly zero, users.
Comment 1 Douglas Bagnall 2025-10-06 08:35:40 UTC
Created attachment 18748 [details]
Combined patch for 4.17

Vendors, patchsets with fixes and tests for recent versions are on the individual bugs (bug 15885 and bug 15903). The fixes are simple and will apply a long way back, though the tests end up with resolvable conflicts as you go back.

I am attaching here a combined patchset for 4.17.
Comment 2 Douglas Bagnall 2025-10-09 09:16:21 UTC
Vendors, 

My apologies -- I opened this bug to the Samba-Vendors group, but did not add samba-vendor@samba.org to the CC list.

As you will see, there are two bugs; one that is serious that probably affects nobody, and one that is moderate but will affect more people.
Comment 3 Douglas Bagnall 2025-10-16 02:51:56 UTC
Removing samba-vendors CC and viewing restrictions.