Samba 4.23.11 Ships Five Bundled CVEs and Critical AD Security Fixes
Samba has dropped version 4.23.11, a stable point update that folds five previously disclosed CVEs directly into the 41-megabyte tarball. The most urgent patches cover two 8.8-rated flaws that let low-privilege accounts hijack Active Directory domains or extract gMSA root keys. Beyond the security work, the build resolves CephFS snapshot panics, CTDB cluster race conditions, and a regression that broke Windows-to-Samba trust paths.
Samba 4.23.11 Ships Five Bundled CVEs and Critical AD Security Fixes @ Linux Compatible
Samba 4.23.11 Ships Five Bundled CVEs and Critical AD Security Fixes
Samba has released version 4.23.11, which includes five bundled CVEs and critical security fixes for Active Directory. The most pressing vulnerabilities, rated 8.8 out of 10, allow low-privilege users to hijack domains and access sensitive root keys. In addition to security patches, this update improves stability by addressing issues such as memory leaks and race conditions that have affected production environments. Users are encouraged to upgrade immediately to mitigate security risks and to resolve operational challenges, especially those using CephFS and Windows trust relationships
