REDHAT-BUG-2370453: Medium severity samba vulnerability
Published Jun 5, 2025
·Updated
All versions of Samba starting with 4.21.0 are vulnerable to a improper authorization issue. smbd does not pick up group membership changes when re-authenticating an expired SMB session.
Affected Software
1 affected component
Samba Samba>=4.21.0
Event History
Jun 5, 2025
Data Sourced
via Red Hat·04:34 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2370453?
The severity of REDHAT-BUG-2370453 is categorized as a high severity due to improper authorization issues.
2
How do I fix REDHAT-BUG-2370453?
To fix REDHAT-BUG-2370453, upgrade Samba to a version higher than 4.21.0 to address the improper authorization vulnerability.
3
Which versions of Samba are affected by REDHAT-BUG-2370453?
All versions of Samba starting from 4.21.0 are affected by REDHAT-BUG-2370453.
4
What type of issue is described in REDHAT-BUG-2370453?
REDHAT-BUG-2370453 describes an improper authorization issue related to group membership changes and expired SMB sessions.
5
Can REDHAT-BUG-2370453 lead to security breaches?
Yes, REDHAT-BUG-2370453 can potentially lead to security breaches by not recognizing relevant group membership changes.