CVE-2025-0620: Samba

Medium severity, CVSS 4.9. EPSS: 0.7% chance of exploitation in the next 30 days.

A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.

Affected products

  • Samba Samba: from 4.21.0, before 4.21.6 (fixed in 4.21.6); from 4.22.0, before 4.22.2 (fixed in 4.22.2)

Published 2025-06-06. Last modified 2026-08-31.