This update for samba fixes the following issues:
- CVE-2021-20251: Fixed an issue where the bad password count would not be
properly incremented, which could allow attackers to brute force a
user's password (bsc#1206546).
- CVE-2022-38023: Disabled weak ciphers by default in the Netlogon Secure
channel (bsc#1206504).
- CVE-2022-37966: Fixed an issue where a weak cipher would be selected to
encrypt session keys, which could lead to privilege escalation
(bsc#1205385).
Patch Instructions:
To install this SUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.4:
zypper in -t patch openSUSE-SLE-15.4-2023-163=1
- SUSE Linux Enterprise Server for SAP 15-SP2:
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-163=1
- SUSE Linux Enterprise Server 15-SP2-LTSS:
zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-163=1
- SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS:
zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-163=1
- SUSE Linux Enterprise High Availability 15-SP2:
zypper in -t patch SUSE-SLE-Product-HA-15-SP2-2023-163=1
- SUSE Enterprise Storage 7:
zypper in -t patch SUSE-Storage-7-2023-163=1
- openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):
libndr0-4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0-debuginfo-4.11.14+git.384.5dc2c21dce-150200.4.44.1
- openSUSE Leap 15.4 (x86_64):
libndr0-32bit-4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr0-32bit-debuginfo-4.11.14+git.384.5dc2c21dce-150200.4.44.1
- SUSE Linux Enterprise Server for SAP 15-SP2 (ppc64le x86_64):
libdcerpc-binding0-4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-binding0-debuginfo-4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-devel-4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-samr-devel-4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-samr0-4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc-samr0-debuginfo-4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0-4.11.14+git.384.5dc2c21dce-150200.4.44.1
libdcerpc0-debuginfo-4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-devel-4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac-devel-4.11.14+git.384.5dc2c21dce-150200.4.44.1
libndr-krb5pac0-4.11.14+git.384.5dc2c2...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2021-20251.html
https://www.suse.com/security/cve/CVE-2022-37966.html
https://www.suse.com/security/cve/CVE-2022-38023.html
https://bugzilla.suse.com/1205385
https://bugzilla.suse.com/1206504
https://bugzilla.suse.com/1206546
Get the latest Linux and open source security news straight to your inbox.