Security update scheduled by upsteam for: Wednesday 2021-03-24 CVE-2020-27840 CVE-2021-20277
Patches applied: svn patches r19309 + r19310 9000_bug52916_CVE-2020-27840-patch-for-obsolete-versions.quilt 9001_bug52916_CVE-2021-20277-ldb_handler_fold-for-4.12.quilt ldb 2:1.5.8-1A~4.4.0.202103221908 (in scope ucs_4.4-0-errata4.4-7) The issue is in ldb, therefore they do not have to be applied to the samba src package, this was done for thoroughness. svn patches r19305 + r19306 99_bug52916_CVE-2020-27840-patch-for-obsolete-versions.quilt 99_bug52916_CVE-2021-20277-ldb_handler_fold-for-4.12.quilt samba 2:4.10.18-1A~4.4.0.202103181228 (in scope ucs_4.4-0-errata4.4-7) OK: CVE-2020-27840 POC `explode_ldb_dn_explode` shows no memory leaks with new version
Created attachment 10660 [details] samba.yaml
Created attachment 10661 [details] ldb.yaml
* Samba installation of new version: OK * Update samba to new version: OK * update tests: OK * samba-tests: OK * s4con- test: OK * Installation of univention-ldb-modules: OK * Samba team reproducer does not show memory error any more: OK * Yaml: OK Verified
<https://errata.software-univention.de/#/?erratum=4.4x929> <https://errata.software-univention.de/#/?erratum=4.4x930>