[CLSA-2026:1777945598] Fix CVE(s): CVE-2020-25717, CVE-2020-25719, CVE-2020-25722
Type:
security
Severity:
Important
Release date:
2026-05-05 01:46:44 UTC
Description:
* SECURITY UPDATE: domain user can become root on a domain member by renaming a machine account - debian/patches/CVE-2020-25717.patch: backport the el6/ol6 8-commit subset (samba 3.6.23 precedent); introduce the new "min domain uid" smb.conf parameter (default 1000) and enforce it in check_account() so a domain logon resolving to a uid below the threshold is rejected with NT_STATUS_INVALID_TOKEN, drop the DOMAIN\user to user prefix-stripping fallback in smb_getpwnam(), stop autocreating local users from check_account() and from the kerberos guest fallback by passing create=false, drop the !winbind_ping() branch in create_local_token() so a missing winbindd no longer silently switches the unix-token computation, and require a PAC in any domain mode (DC or member) inside gensec_generate_session_info_pac() returning NT_STATUS_NO_IMPERSONATION_TOKEN otherwise (the gensec hunk is the jointly tagged CVE-2020-25717+CVE-2020-25719 commit, so this update also delivers the member-server portion of CVE-2020-25719; the DC-side portion of CVE-2020-25719 is tracked separately under ELSCVE-104393) - CVE-2020-25717 * SECURITY UPDATE: privileged attribute escalation and structural objectclass change in active directory ldap server - debian/patches/CVE-2020-25722.patch: in source4/dsdb/samdb/ldb_modules/objectclass.c, capture the current structural objectclass at the start of objectclass_do_mod and reject any modify that would change it; in source4/dsdb/samdb/ldb_modules/samldb.c, factor the domain ntSecurityDescriptor lookup into samldb_get_domain_secdesc() and add samldb_check_sensitive_attributes() invoked from samldb_add() and samldb_modify() to refuse non-system writes to sidHistory, gate msDS-SecondaryKrbTgtNumber on the DS-Install-Replica extended right, and gate msDS-AllowedToDelegateTo on SePrivEnableDelegation - CVE-2020-25722
Updated packages:
  • ctdb_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:9489df285943770d7f0c976a11d219c27dc99cd6
  • libnss-winbind_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:db541586aa9629e0ce45d77196ff80980d614a9a
  • libpam-winbind_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:8c2dee8934f82fa734d71f8665ad3bb90258f8f0
  • libparse-pidl-perl_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:ef64938e8d1b127469fe1c3e8f9670c6d3f10627
  • libsmbclient_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:5710090efe067155b069d2ce009105506ea7d433
  • libsmbclient-dev_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:009745c95eadf42b40a8057bbc1f018035b51e5a
  • libwbclient-dev_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:4b6054e9a7874b44c940e2125be91cd0671234de
  • libwbclient0_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:bd3864652227ecc30461ee452b0cb192ea4f1d0d
  • python-samba_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:68281619b857f4a0fc6adda7ce850b65a6240f38
  • registry-tools_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:cecac10e6e207b839e1d002edb7e3378e193b095
  • samba_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:18880619b55b42593025a1ff20023429878ea6fd
  • samba-common_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_all.deb
    sha:93a4a969525456986b9d93d739c8e83913b5bdd1
  • samba-common-bin_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:d436955d335a8a5131d741599f2724c5be386e03
  • samba-dev_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:3e5b5bca9f459a1f346dddeae767bc3972c90187
  • samba-dsdb-modules_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:4da42d4d6937476b576773fe298bb1a591d1a693
  • samba-libs_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:f028941cea3b0cc05b5ec4ef456141b3aaca75d2
  • samba-testsuite_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:01d351076b84deaada557fa5adc6d79faa12eca2
  • samba-vfs-modules_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:011ff90f2c76fde39e6db6f569f25f81493d3666
  • smbclient_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:5132d5073a0a1ccea79490c5cff36add9187fba4
  • winbind_4.3.11+dfsg-0ubuntu0.16.04.34+tuxcare.els10_amd64.deb
    sha:7ddf10d1a19aad4f3df1cb54df3b60d53222c31c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.