-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 15 Oct 2025 17:21:11 +0300 Source: samba Architecture: source Version: 2:4.23.2+dfsg-1 Distribution: unstable Urgency: medium Maintainer: Debian Samba Maintainers <pkg-samba-maint@lists.alioth.debian.org> Changed-By: Michael Tokarev <mjt@tls.msk.ru> Changes: samba (2:4.23.2+dfsg-1) unstable; urgency=medium . * new upstream security release: * CVE-2025-9640: Uninitialized memory disclosure via vfs_streams_xattr https://www.samba.org/samba/security/CVE-2025-9640.html * CVE-2025-10230: Command injection via WINS server hook script https://www.samba.org/samba/security/CVE-2025-10230.html Checksums-Sha1: e520a60a7acf7ba202b18af598b954da9034f5c6 6088 samba_4.23.2+dfsg-1.dsc 9a0398cc546dd0eae4edb99b3c02f4c50822ad43 25730356 samba_4.23.2+dfsg.orig.tar.xz 331aa1af0ca9645cdfc4879412adc2b4c7863761 188892 samba_4.23.2+dfsg-1.debian.tar.xz 2c14d04c25ba6034efb4b1ecd2ffd8551654941e 6819 samba_4.23.2+dfsg-1_source.buildinfo Checksums-Sha256: 5dbe6f7dd5ea44ae4ebce53554b21701c0eda163eff36065f9daa3cb636d65b9 6088 samba_4.23.2+dfsg-1.dsc 9a3fd48db8230adb0b7d4c2d611492dd83e803e223a902d5b9be77aa1b6956ce 25730356 samba_4.23.2+dfsg.orig.tar.xz 0b599f95aeca8437b748a5aa440865570b2cabc04a3b2a18630e79ba9b66cf74 188892 samba_4.23.2+dfsg-1.debian.tar.xz c4eb04552e4614d449598f0f57b9cf083ed5b19e6277c7d7c3859ce353e0ba3c 6819 samba_4.23.2+dfsg-1_source.buildinfo Files: a4b417d9ea1e2c81ef3f3c6b2637827b 6088 net optional samba_4.23.2+dfsg-1.dsc 415bf7aedc11cec0831eb9c50628f17b 25730356 net optional samba_4.23.2+dfsg.orig.tar.xz 9f3b496703d66be9d198c692ee14e50c 188892 net optional samba_4.23.2+dfsg-1.debian.tar.xz bd6b32bb1098dc981929aaceaca9d245 6819 net optional samba_4.23.2+dfsg-1_source.buildinfo -----BEGIN PGP SIGNATURE----- wsG7BAEBCgBvBYJo763tCRCCqkokOx6UeEcUAAAAAAAeACBzYWx0QG5vdGF0aW9u cy5zZXF1b2lhLXBncC5vcmcGVsoIBm3llXVpG8tMOlKzLpzqsS5S7LHwYxtgsqkK dRYhBGSqKrUx1WkDNmv++YKqSiQ7HpR4AAApTw/+LPmyAhP3nTA+spdcJoANowkl kAduLgm4ciQRSg+cfCOI6uZcUuPsDvR5lwBhG+QLQjumdVAEW4qaFcPcVaf4hYFi Oo42US0P7x2IghYNNE9pCSucK2M4SKKoELjxWkU6iG2kyg9pQmgtueKOrznI09uc Hr95GSAveE4EvGpD9B28Y9HXa7na0PWC99AlVWevgS1kN4VEDIMD0pXhmFgMmRMk haCwI1asTmrOLVgjj1Cq4gfmrUKnvdNpJBiZlhrgrcaz1At982FX05SPuh9mQJO8 KzQaQZU6nMFsxz/5G0oPj9wFSiY1nYZ/9Ox1goFBUuUIjmqKX2QMvcRZFI109zy/ u84a+hFd2s7MI0y5L295ErlPcpBDSOUreovKYNulJ17wzmXVaFGCMxQEnip2ywMC wtOsa7bWR2bJvzcaGcXJd/sdYYFgLc2mmNhA3AZvhdXzrW43OC8HS6ll51SSWYmq Yel/Uik9V1VW0/Eh20KGCSR046SMGpbbkYuSBkWgQoqalJiOtQhyhbP0Z7CgnKxG Z8S9fK+rrPvFAiu2RtNjdNV4FoQe/aW+IdIKlcOq9fvh7qnCJfK9XtVxQCsUJRTD 3e2cfurih3bFyeyc8CDxWDOZKlOlveI+i1yrojoNgzOtOzOeCXW71C4G2jxlqaVW mytMeCG3006e+rc73Jw= =pqI2 -----END PGP SIGNATURE-----