Bug 16095 - Use-after-free in handling acls with claims and conditions
Summary: Use-after-free in handling acls with claims and conditions
Status: RESOLVED FIXED
Alias: None
Product: Samba 4.1 and newer
Classification: Unclassified
Component: File services (show other bugs)
Version: unspecified
Hardware: All All
: P5 normal (vote)
Target Milestone: ---
Assignee: Samba release manager
QA Contact: Samba QA Contact
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2026-06-01 10:24 UTC by Volker Lendecke
Modified: 2026-06-08 18:57 UTC (History)
1 user (show)

See Also:


Attachments
Patch for 4.24., 4.23 and 4.22 (2.07 KB, patch)
2026-06-08 12:01 UTC, Volker Lendecke
metze: review+
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Volker Lendecke 2026-06-01 10:24:45 UTC
Have patch, need bugnumber
Comment 1 Samba QA Contact 2026-06-08 11:48:04 UTC
This bug was referenced in samba master:

c137ec34c4aebf889943677f6426583029eb4cd4
Comment 2 Volker Lendecke 2026-06-08 12:01:47 UTC
Created attachment 19013 [details]
Patch for 4.24., 4.23 and 4.22

Patch builds cleanly back to 4.22. I would include it in 4.22.next as well, a use-after-free always smells bad security-wise.
Comment 3 Samba QA Contact 2026-06-08 17:54:12 UTC
This bug was referenced in samba v4-24-test:

fdfa95a48c1dfbf0dc5da7a25ffdd5520de282bb
Comment 4 Samba QA Contact 2026-06-08 18:08:28 UTC
This bug was referenced in samba v4-23-test:

8c76f92d6694db761f2e74fa328acf990ab0b70c
Comment 5 Samba QA Contact 2026-06-08 18:57:03 UTC
This bug was referenced in samba v4-22-test:

5816c92240ce0bec68692f7af500a6ad401ae665