There are 8 open security issues in bullseye.
3 issues left for the package maintainer to handle:
MaxQueryDuration not honoured in Samba AD DC LDAP
(postponed; to be fixed through a stable update)
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.
You can find information about how to handle these issues in the security team's documentation.
2 ignored issues:
A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.