[CLSA-2026:1788174820] Fix CVE(s): CVE-2022-37966
Type:
security
Severity:
Important
Release date:
2026-08-31 11:13:51 UTC
Description:
* SECURITY UPDATE: Kerberos KDC elevation of privilege via weak RC4 session keys - debian/patches/CVE-2022-37966.patch: prefer AES over RC4 for Kerberos session keys by selecting the session key from the server's advertised session etypes, strip weak keys from the krbtgt account, leave UF_USE_DES_KEY_ONLY accounts without usable keys as upstream does, declare RC4 support explicitly on trust objects created by samba-tool (upstream 84c28b05a0a), and add "kdc default domain supported enctypes", "kdc supported enctypes" and "kdc force enable rc4 weak session keys" options - debian/patches/CVE-2022-37966.patch: free the newly added sdb_entry etypes/session_etypes members, the calloc'ed etypes->val array, and the krbtgt keys discarded when the key list is truncated to one (upstream 75a1beeea85, a97aad91878, 149d4364299), avoiding a per-request KDC memory leak - debian/patches/CVE-2022-37966-domain-trust-modify.patch: add the upstream "samba-tool domain trust modify" command (upstream d1999c15, same CVE-2022-37966 series) so an administrator has a supported CLI to repair a pre-existing RC4-only trust after the change above stopped assuming RC4 support on trust objects - CVE-2022-37966
CVEs fixed:
Updated packages:
  • ctdb_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:cf41dce9d3136256964ffa1c4e3d6358888ef595
  • libnss-winbind_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:3ae04fe5af3470eecef2ddcb3993e6d0232bf7dd
  • libpam-winbind_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:50e045fa8de6da8e73f3f233b6afbbc1fb281073
  • libparse-pidl-perl_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:e94441ed21a65253bab93dc5da806c1ef8b3fa90
  • libsmbclient_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:b284fe128c29f2f5b166074c8c5d3ecbd2cc0c95
  • libsmbclient-dev_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:47f942fc3d53677dd7779037d9bf234477b7d356
  • libwbclient-dev_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:6f92fb3bf615d5df560d17dc3caa7f40030a4d24
  • libwbclient0_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:b1aa64ea7473e1d2fc6123695b90379a0435fa87
  • python-samba_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:39bae33286334eb186657c474bfdd197b7f8d8d7
  • registry-tools_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:bc3edd714eb72d2713719d91f27ad6cb903744d6
  • samba_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:86725c8824ef46c0dbde85f6a0c72b82a9eef1d1
  • samba-common_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_all.deb
    sha:9cc7a1d89d776a9fd433624fb8b2f2793b1a8254
  • samba-common-bin_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:7dc83050d3bb10a49fa3e9dd0d3c0aaea682c012
  • samba-dev_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:4387e57255737ebc5dc97b2cb0359f576ea698aa
  • samba-dsdb-modules_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:ab6287ee4fd67ea6a6859c1424428aee1c1d92d0
  • samba-libs_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:06095aa90c0e45542016ff69eac266acaf13eb9b
  • samba-testsuite_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:49ac3fe43fe45e253b351ebc16fec38502def36e
  • samba-vfs-modules_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:c4863974bf39cc6ff740a9a5038d4ea16179d976
  • smbclient_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:929fe1694e9e4378f003a88102aeae7e9261bdc0
  • winbind_4.7.6+dfsg~ubuntu-0ubuntu2.29+tuxcare.els9_amd64.deb
    sha:b25207c4fcb7134d0337d977cbca163509dbd502
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.