CVE-2025-0620

Name
CVE-2025-0620
Description
A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vdb-entry https://access.redhat.com/security/cve/CVE-2025-0620
issue-tracking https://bugzilla.redhat.com/show_bug.cgi?id=2370453
secalert@redhat.com https://www.samba.org/samba/security/CVE-2025-0620.html
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/06/03/8

Match rules

CPE URI Source package Min version Max version
shopxo >= 4.21.0 < 4.21.6
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* samba >= 4.21.0 < 4.21.6
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* samba >= 4.22.0 < 4.22.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
samba edge-main 4.21.6-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
samba edge-main 4.21.4-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
samba edge-main 4.21.4-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
samba edge-main 4.21.4-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
samba edge-main 4.21.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
samba edge-main 4.21.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
samba 3.22-main 4.21.6-r0 None fixed
samba 3.22-main 4.21.4-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable