<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE1-SA-2024-0046</id>
    <title>An update for samba is now available for HCE 1.1</title>
    <severity>Important</severity>
    <release>HCE 1.1</release>
    <issued date="2024-09-27 08:26:20"/>
    <updated date="2024-09-27 08:26:20"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2020-25721" id="CVE-2020-25721" title="CVE-2020-25721 Base Score: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2022-38023" id="CVE-2022-38023" title="CVE-2022-38023 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2020-25719" id="CVE-2020-25719" title="CVE-2020-25719 Base Score: 7.2 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets. (CVE-2020-25721)

Netlogon RPC Elevation of Privilege Vulnerability (CVE-2022-38023)

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise. (CVE-2020-25719)
</description>
    <pkglist>
      <collection short="HCE 1.1" package="samba">
        <name>HCE 1.1</name>
        <package arch="x86_64" name="ctdb" version="4.10.16" release="25.hce1c">
          <filename>ctdb-4.10.16-25.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="libsmbclient" version="4.10.16" release="25.hce1c">
          <filename>libsmbclient-4.10.16-25.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="libwbclient" version="4.10.16" release="25.hce1c">
          <filename>libwbclient-4.10.16-25.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="samba" version="4.10.16" release="25.hce1c">
          <filename>samba-4.10.16-25.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="samba-client" version="4.10.16" release="25.hce1c">
          <filename>samba-client-4.10.16-25.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="samba-client-libs" version="4.10.16" release="25.hce1c">
          <filename>samba-client-libs-4.10.16-25.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="noarch" name="samba-common" version="4.10.16" release="25.hce1c">
          <filename>samba-common-4.10.16-25.hce1c.noarch.rpm</filename>
        </package>
        <package arch="x86_64" name="samba-common-libs" version="4.10.16" release="25.hce1c">
          <filename>samba-common-libs-4.10.16-25.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="samba-common-tools" version="4.10.16" release="25.hce1c">
          <filename>samba-common-tools-4.10.16-25.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="samba-libs" version="4.10.16" release="25.hce1c">
          <filename>samba-libs-4.10.16-25.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="samba-python" version="4.10.16" release="25.hce1c">
          <filename>samba-python-4.10.16-25.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="samba-winbind" version="4.10.16" release="25.hce1c">
          <filename>samba-winbind-4.10.16-25.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="samba-winbind-modules" version="4.10.16" release="25.hce1c">
          <filename>samba-winbind-modules-4.10.16-25.hce1c.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
