CVE-2025-0620: Samba
Medium severity, CVSS 4.9. EPSS: 0.7% chance of exploitation in the next 30 days.
A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.
Affected products
- Samba Samba: from 4.21.0, before 4.21.6 (fixed in 4.21.6); from 4.22.0, before 4.22.2 (fixed in 4.22.2)
Published 2025-06-06. Last modified 2026-08-31.