Unrated severityOSV Advisory· Published Jun 6, 2025· Updated Mar 18, 2026
Samba: smbd doesn't pick up group membership changes when re-authenticating an expired smb session
CVE-2025-0620
Description
A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.
Affected products
5samba-4.21.0, samba-4.21.1, samba-4.21.2, …+ 1 more
- (no CPE)range: samba-4.21.0, samba-4.21.1, samba-4.21.2, …
- (no CPE)
- osv-coords3 versionspkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweedpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP7pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7
< 4.22.2+git.396.c752843dcf4-1.1+ 2 more
- (no CPE)range: < 4.22.2+git.396.c752843dcf4-1.1
- (no CPE)range: < 4.21.6+git.402.80f493f530f-150700.3.3.1
- (no CPE)range: < 4.21.6+git.402.80f493f530f-150700.3.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- access.redhat.com/security/cve/CVE-2025-0620mitrevdb-entryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitreissue-trackingx_refsource_REDHAT
- www.samba.org/samba/security/CVE-2025-0620.htmlmitre
News mentions
0No linked articles in our index yet.