-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 27 Dec 2025 10:40:36 +0100 Source: smb4k Binary: smb4k smb4k-dbgsym Architecture: armel Version: 4.0.0-1+deb13u1 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-03) Changed-By: Salvatore Bonaccorso Description: smb4k - Samba (SMB) share advanced browser Closes: 1122381 Changes: smb4k (4.0.0-1+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix two security issues in the KAuth mounthelper: - CVE-2025-66002: local users can perform arbitrary unmounts via smb4kmounthelper due to lack of input validation - CVE-2025-66003: local users can perform a local root exploit via smb4k mounthelper if they can access and control the contents of a Samba share (Closes: #1122381) * Merge Smb4KHardwareInterface class from master so that the merged security fixes can be compiled Checksums-Sha1: 1046d47ef60f469b8f2aeafc76febe501e23c4f1 11688684 smb4k-dbgsym_4.0.0-1+deb13u1_armel.deb 3e29c510ef4091c5395fde54f07de585e85f24d2 21663 smb4k_4.0.0-1+deb13u1_armel-buildd.buildinfo d11217991ef30b1e798dc2764ff8a9a071dbd48e 5071344 smb4k_4.0.0-1+deb13u1_armel.deb Checksums-Sha256: a44c03e31fcdc140049c143b86493227e2cf14d3f67d5c96b2edaadcd37f6c63 11688684 smb4k-dbgsym_4.0.0-1+deb13u1_armel.deb e52e9abe7d115bb2065e2b1ce66488a92f1a1a3fd01437a9f225237fbbd68cb9 21663 smb4k_4.0.0-1+deb13u1_armel-buildd.buildinfo bfca83b6a08164117947d0ca189c9170737485c017c0725ad9127ad1ac9487b5 5071344 smb4k_4.0.0-1+deb13u1_armel.deb Files: b159fb051181d6599c5ccfdfbb303596 11688684 debug optional smb4k-dbgsym_4.0.0-1+deb13u1_armel.deb 97dbb9e3e398bc1e1657f7b1a948c6b8 21663 kde optional smb4k_4.0.0-1+deb13u1_armel-buildd.buildinfo 562f61372d9473feb307515c91557398 5071344 kde optional smb4k_4.0.0-1+deb13u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEENsdrABvTD8MQ0UffVza3l394K2AFAmlVF4kACgkQVza3l394 K2DaSRAA1mD/Hjdu/8Znd6UvzP/BVErQyVgAZgWd0ovFyCmd/5vD76XWD5mMLWmt EBz9GxgcbBLA7mEECJPn7Rbx7tO21+fC9fqA9/y9VNoNMtCRJcMNval3O4xtrYE5 V9kaLhkyuC9Fjs1KyMM8mag4dlnxPw2ljQTJGBNolllcv6HSVT6mTmrfLVE88P/8 kWAmM25C3TMTDAygDQawlyH0CWFTGjlI3gFnfLxkmuSDBG3b6bpiIIDxdI0LpjLj REQsohKGe0QRE8EZ2LJR9JRI1NKG0Hpb24h/pYi+Ya7RIoKjSyhPUxzgxmtKSo8P SnZhc60AQQ0gTgbHQXb4rluGdMrkghDXaHuAvbidQeKVu4GcvYQ05eTU+WohP1Ir CLytml40HixzBvYNvMuoOeO3q9PLw06HAGagZGYPDxeosE8csxQySFCP2qRJref4 79D/aJSUjI/7O2BGUcMf8G38Y+FRbL+sLjU+I/BvQEsTxlNfpwMJrxmSJn0E9qbk 1pd0/2yBf2a3JY6ioi7pxDV6Xw2aDCUbWm7szY0jHv/sU5/bFxfS8iXJeSdHcspl G+oBFdid7RT8gECR/uPVcOfvL1aB6cBLhBqM63CY3f/y2XltFfBIptoEJF7Npx3y 2T8MFj0ybnTRQj1P2QCxLieTi4nqd2bxde48i5UL3AbO1/08ZcY= =mzEA -----END PGP SIGNATURE-----