<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 23:00:32 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:4325 — Moderate: samba security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:4325</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: ctdb, AlmaLinux:9: libnetapi, AlmaLinux:9: libnetapi-devel, AlmaLinux:9: libsmbclient, AlmaLinux:9: libsmbclient-devel, AlmaLinux:9: libwbclient, AlmaLinux:9: libwbclient-devel, AlmaLinux:9: python3-samba, AlmaLinux:9: python3-samba-dc, AlmaLinux:9: python3-samba-devel and 24 more&lt;/p&gt;
&lt;p&gt;Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* samba: SMB2 packet signing is not enforced when &amp;#34;server signing = required&amp;#34; is set (CVE-2023-3347)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* The trust relationship between this workstation and the primary domain failed (BZ#2223600)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: ctdb, AlmaLinux:9: libnetapi, AlmaLinux:9: libnetapi-devel, AlmaLinux:9: libsmbclient, AlmaLinux:9: libsmbclient-devel, AlmaLinux:9: libwbclient, AlmaLinux:9: libwbclient-devel, AlmaLinux:9: python3-samba, AlmaLinux:9: python3-samba-dc, AlmaLinux:9: python3-samba-devel and 24 more&lt;/p&gt;
&lt;p&gt;Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* samba: SMB2 packet signing is not enforced when &amp;#34;server signing = required&amp;#34; is set (CVE-2023-3347)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* The trust relationship between this workstation and the primary domain failed (BZ#2223600)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:4325</guid>
    </item>
    <item>
      <title>bdu:2024-01904</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-01904</link>
      <description>bdu:2024-01904</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-01904</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0603 — De multiples vulnérabilités ont été découvertes dans Samba. Certaines
d'entre elles permettent à un attaquant de provoq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0603</link>
      <description>certfr-2023-avi-0603</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0603</guid>
    </item>
    <item>
      <title>EUVD-2026-261475</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-261475</link>
      <description>EUVD-2026-261475</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-261475</guid>
    </item>
    <item>
      <title>fkie_cve-2023-3347</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3347</link>
      <description>&lt;p&gt;A vulnerability was found in Samba&amp;#39;s SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured &amp;#34;server signing = required&amp;#34; or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the network traffic and modifying the SMB2 messages between client and server, affecting the integrity of the data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in Samba&amp;#39;s SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured &amp;#34;server signing = required&amp;#34; or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the network traffic and modifying the SMB2 messages between client and server, affecting the integrity of the data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-3347</guid>
    </item>
    <item>
      <title>GHSA-m82c-5hpw-48f7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m82c-5hpw-48f7</link>
      <description>&lt;p&gt;A vulnerability was found in Samba&amp;#39;s SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured &amp;#34;server signing = required&amp;#34; or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the network traffic and modifying the SMB2 messages between client and server, affecting the integrity of the data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in Samba&amp;#39;s SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured &amp;#34;server signing = required&amp;#34; or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the network traffic and modifying the SMB2 messages between client and server, affecting the integrity of the data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m82c-5hpw-48f7</guid>
    </item>
    <item>
      <title>gsd-2023-3347</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-3347</link>
      <description>gsd-2023-3347</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-3347</guid>
    </item>
    <item>
      <title>OESA-2023-1452 — samba security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1452</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: samba&lt;/p&gt;
&lt;p&gt;Samba is a suite of programs for Linux and Unix to interoperate with Windows.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.(CVE-2022-2127)&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Samba&amp;amp;apos;s SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured &amp;amp;quot;server signing = required&amp;amp;quot; or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the network traffic and modifying the SMB2 messages between client and server, affecting the integrity of the data.(CVE-2023-3347)&lt;/p&gt;
&lt;p&gt;An infinite loop vulnerability was found in Samba&amp;amp;apos;s mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: samba&lt;/p&gt;
&lt;p&gt;Samba is a suite of programs for Linux and Unix to interoperate with Windows.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.(CVE-2022-2127)&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Samba&amp;amp;apos;s SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured &amp;amp;quot;server signing = required&amp;amp;quot; or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the network traffic and modifying the SMB2 messages between client and server, affecting the integrity of the data.(CVE-2023-3347)&lt;/p&gt;
&lt;p&gt;An infinite loop vulnerability was found in Samba&amp;amp;apos;s mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1452</guid>
    </item>
    <item>
      <title>RHSA-2023:4325 — Red Hat Security Advisory: samba security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:4325</link>
      <description>&lt;p&gt;samba: SMB2 packet signing is not enforced when &amp;#34;server signing = required&amp;#34; is set&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;samba: SMB2 packet signing is not enforced when &amp;#34;server signing = required&amp;#34; is set&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:4325</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2023-3347</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3347</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: samba, Ubuntu:22.04:LTS: samba&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Samba&amp;#39;s SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured &amp;#34;server signing = required&amp;#34; or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the network traffic and modifying the SMB2 messages between client and server, affecting the integrity of the data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: samba, Ubuntu:22.04:LTS: samba&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Samba&amp;#39;s SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured &amp;#34;server signing = required&amp;#34; or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the network traffic and modifying the SMB2 messages between client and server, affecting the integrity of the data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3347</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1842 — Samba: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1842</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Samba ausnutzen, um einen Denial of Service Angriff durchzuführen, Daten zu manipulieren und Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Samba ausnutzen, um einen Denial of Service Angriff durchzuführen, Daten zu manipulieren und Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1842</guid>
    </item>
  </channel>
</rss>
