The vendor explicitly identifies these products as affected by this CVE.
- ldb-tools as a component of Red Hat Enterprise Linux 10
- libldb as a component of Red Hat Enterprise Linux 10
- libldb-devel as a component of Red Hat Enterprise Linux 10
- libnetapi as a component of Red Hat Enterprise Linux 10
- libnetapi-devel as a component of Red Hat Enterprise Linux 10
- libsmbclient as a component of Red Hat Enterprise Linux 10
- libsmbclient-devel as a component of Red Hat Enterprise Linux 10
- libwbclient as a component of Red Hat Enterprise Linux 10
- libwbclient-devel as a component of Red Hat Enterprise Linux 10
- python3-ldb as a component of Red Hat Enterprise Linux 10
- python3-samba as a component of Red Hat Enterprise Linux 10
- python3-samba-dc as a component of Red Hat Enterprise Linux 10
- Summary
- A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.
- Remediation
- Fix deferred
