-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 27 Dec 2025 10:40:36 +0100 Source: smb4k Binary: smb4k smb4k-dbgsym Architecture: armhf Version: 4.0.0-1+deb13u1 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-04) Changed-By: Salvatore Bonaccorso Description: smb4k - Samba (SMB) share advanced browser Closes: 1122381 Changes: smb4k (4.0.0-1+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix two security issues in the KAuth mounthelper: - CVE-2025-66002: local users can perform arbitrary unmounts via smb4kmounthelper due to lack of input validation - CVE-2025-66003: local users can perform a local root exploit via smb4k mounthelper if they can access and control the contents of a Samba share (Closes: #1122381) * Merge Smb4KHardwareInterface class from master so that the merged security fixes can be compiled Checksums-Sha1: b3b87e9a37f25bfe39fa95b7a7ab393030c181bf 11724200 smb4k-dbgsym_4.0.0-1+deb13u1_armhf.deb a46468abd0c322bdb12f154b371554dcad42b003 21677 smb4k_4.0.0-1+deb13u1_armhf-buildd.buildinfo 3a8d896256b1b9de98f883dca2c9c3b35f742bcb 5077004 smb4k_4.0.0-1+deb13u1_armhf.deb Checksums-Sha256: 6c0dba3a45bc42a20efad0cfbe7cae71a5e7818a5bbacb6c634b679f79f5fc4d 11724200 smb4k-dbgsym_4.0.0-1+deb13u1_armhf.deb 33c194984bab3ea524fb5e985f6f22282fb258a91b9a2b325995c25e567986d3 21677 smb4k_4.0.0-1+deb13u1_armhf-buildd.buildinfo 121c20d2e7d77390d68c490d96d03e95c9137080ff23ea9d9e64d0aea0201db3 5077004 smb4k_4.0.0-1+deb13u1_armhf.deb Files: c86f0e48b5955ec1a6373cb9f45de594 11724200 debug optional smb4k-dbgsym_4.0.0-1+deb13u1_armhf.deb 60a08bdcb08a49994a41ff91bab07dbf 21677 kde optional smb4k_4.0.0-1+deb13u1_armhf-buildd.buildinfo 3c5eecedde207dbcbca44ed5460d2b36 5077004 kde optional smb4k_4.0.0-1+deb13u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEUPFH3FhY8nQZGtLwVLd4YzMSDKEFAmlVF3cACgkQVLd4YzMS DKHc6RAA0aP15F/QafSvxuxGE+9kfyXqwWieCP6e13hffUUb9oZcYtWCi8n74rrj yxFpmJvuGJoJlUgpNcI+Jevc5qMtHt0QnV15DkTUUSrsE05ByW7IpxUqh6dtJwC5 /5WI6R1mInFwO/dix82EchN77703MdYp/7t+FCn2neX+sLiIjHE621nSVX1RS52A L4xpnRUruk50Ns/GJcHy5+JmcZbhZnJYvnUBvucudvyoF1mdXzqUAjUKuI41d2JB YLdVCFtWyXrAW/j4EWZHYvrknsq8+kIs707M5v5OwvHjE4li6y+ntPK1csKft4cF t6hq9XXNO96E5akkB19WUM1T+7ExN7vBR4/krzMNgu9ZmhEwjs6nU0KjAayEKPNj zO/wfIksyynKxHRtF8dJvobd180+o/tm4VsLpWua8tFO2TRo46vGsmfGMO34J1N5 O/AfPuhSTxHR+bOtbVbGQjzbIED3+AakkPRmyV3iwvYpKhBbMrSzD7j4eToOUsPu iVFfEMQrayw+Sc65fT4JHLTESvwnaqYn6FW80whW9UK2qKO8jV8aKZLMbJcX/g35 UEfiJQHb+z6dd9VDJHc4ZBX+XhkFYyo0sdd3WAWJZba/DXa/AyTbK0+7fzPqdByd qotjk47JNMxkH8i2qho6WS9/qdp7oCV2zHr3tX7mjOBwTJaiJT0= =xCBh -----END PGP SIGNATURE-----