Release Planning for Samba 4.13

From SambaWiki
The printable version is no longer supported and may have rendering errors. Please update your browser bookmarks and please use the default browser print function instead.

Samba 4.13 has been marked discontinued.

Release blocking bugs

Samba 4.13.17

(Updated 31-January-2022)

  • Monday, January 31 2022 - Samba 4.13.17 has been released as a Security Release to address the following defects:
    • CVE-2021-44142 (Out-of-Bound Read/Write on Samba vfs_fruit module.)
    • CVE-2022-0336 (Re-adding an SPN skips subsequent SPN conflict checks.)
 Release Notes Samba 4.13.17

Samba 4.13.16

(Updated 10-January-2022)

  • Monday, January 9 2022 - Samba 4.13.16 has been released as a Security Release to address the following defects:
    • CVE-2021-43566 (Symlink race error can allow directory creation outside of the exported share.)

Samba 4.13.15

(Updated 15-December-2021)

  • Wednesday, December 15 2021 - Samba 4.13.15 has been released to address the following regressions:
    • CVE-2020-25717 (A user on the domain can become root on domain members)
    • BUG-14902 (User with multiple spaces (eg Fred<space><space>Nurk) become un-deletable)

Samba 4.13.14

(Updated 09-November-2021)

  • Tuesday, November 9 2021 - Samba 4.13.14 has been released as a Security Release to address the following defects:
    • CVE-2020-25717 (A user in an AD Domain could become root on domain members)
    • CVE-2020-25718 (Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC)
    • CVE-2020-25719 (Samba AD DC did not always rely on the SID and PAC in Kerberos tickets)
    • CVE-2020-25721 (Kerberos acceptors need easy access to stable AD identifiers (eg objectSid))
    • CVE-2020-25722 (Samba AD DC did not do sufficient access and conformance checking of data stored)
    • CVE-2016-2124 (SMB1 client connections can be downgraded to plaintext authentication)
    • CVE-2021-3738 (Use after free in Samba AD DC RPC server)
    • CVE-2021-23192 (Subsequent DCE/RPC fragment injection vulnerability)
 Release Notes Samba 4.13.14

Samba 4.13.13

(Updated 29-October-2021)

  • Friday, October 29 2021 - Samba 4.13.13 has been released. There will be security releases only beyond this point.
Release Notes Samba 4.13.13

Samba 4.13.12

(Updated 29-October-2021)

  • Wednesday, September 22 2021 - Samba 4.13.12 has been released.
Release Notes Samba 4.13.12

Samba 4.13.11

(Updated 10-September-2021)

  • Tuesday, September 7 2021 - Samba 4.13.11 has been released.
Release Notes Samba 4.13.11

Samba 4.13.10

(Updated 14-July-2021)

  • Wednesday, July 14 2021 - Samba 4.13.10 has been released.
Release Notes Samba 4.13.10

Samba 4.13.9

(Updated 11-May-2021)

  • Tuesday, May 11 2021 - Samba 4.13.9 has been released.
Release Notes Samba 4.13.9

Samba 4.13.8

(Updated 29-April-2021)

  • Thursday, April 29 2021 - Samba 4.13.8 has been released as a security release to address the following defect:
    • CVE-2021-20254 (Negative idmap cache entries can cause incorrect group entries in the Samba file server process token).
Release Notes Samba 4.13.8

Samba 4.13.7

(Updated 24-March-2021)

  • Wednesday, March 24 2021 - Samba 4.13.7 has been released as a security release
 Release Notes Samba 4.13.7

Samba 4.13.6

(Updated 24-March-2021)

  • Wednesday, March 24 2021 - Samba 4.13.6 has been released as a security release
 Release Notes Samba 4.13.6

Samba 4.13.5

(Updated 09-March-2021)

 Release Notes Samba 4.13.5

Samba 4.13.4

(Updated 26-January-2021)

 Release Notes Samba 4.13.4

Samba 4.13.3

(Updated 15-December-2020)

  • Tuesday, December 15 2020 - Samba 4.13.3 has been released.
 Release Notes Samba 4.13.3

Samba 4.13.2

(Updated 03-November-2020)

  • Tuesday, November 03 2020 - Samba 4.13.2 has been released.
 Release Notes Samba 4.13.2

Samba 4.13.1

(Updated 29-October-2020)

  • Thursday, October 29 2020 - Samba 4.13.1 has been released as a Security Release to address the following defects:
    • CVE-2020-14318 (Missing handle permissions check in SMB1/2/3 ChangeNotify).
    • CVE-2020-14323 (Unprivileged user can crash winbind).
    • CVE-2020-14383 (An authenticated user can crash the DCE/RPC DNS with easily crafted records).
 Release Notes Samba 4.13.1

Samba 4.13.0

(Updated 22-September-2020)

  • Tuesday, September 22 2020 - Samba 4.13.0 has been released.
 Release Notes Samba 4.13.0

Samba 4.13.0rc5

(Updated 15-September-2020)

  • Monday, September 15 2020 - Samba 4.13.0rc5 has been released.
 https://download.samba.org/pub/samba/rc/samba-4.13.0rc5.WHATSNEW.txt

Samba 4.13.0rc4

(Updated 07-September-2020)

  • Monday, September 07 2020 - Samba 4.13.0rc4 has been released.
 https://download.samba.org/pub/samba/rc/samba-4.13.0rc4.WHATSNEW.txt

Samba 4.13.0rc3

(Updated 28-August-2020)

  • Friday, August 28 2020 - Samba 4.13.0rc3 has been released.
 https://download.samba.org/pub/samba/rc/samba-4.13.0rc3.WHATSNEW.txt

Samba 4.13.0rc2

(Updated 14-August-2020)

  • Friday, August 14 2020 - Samba 4.13.0rc2 has been released.
 https://download.samba.org/pub/samba/rc/samba-4.13.0rc2.WHATSNEW.txt

Samba 4.13.0rc1

(Updated 09-July-2020)

  • Thursday, July 9 2020 - Samba 4.13.0rc1 has been released.
 https://download.samba.org/pub/samba/rc/samba-4.13.0rc1.WHATSNEW.txt