A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.
2025-06-06T14:15:21.247
2025-11-18T15:46:16.790
Analyzed
CVSSv3.1: 6.6 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | samba | samba | < 4.21.6 | Yes |
| Application | samba | samba | < 4.22.2 | Yes |