CVE-2025-0620
Samba vulnerability analysis and mitigation

Overview

CVE-2025-0620 is a security vulnerability in Samba affecting all versions starting with 4.21.0. The vulnerability was discovered and disclosed in June 2025, where Samba fails to properly handle group membership changes during SMB session re-authentication when using Kerberos authentication. This issue affects Samba's handling of user permissions and group memberships in Active Directory environments (Samba Security).

Technical details

When using Kerberos authentication, SMB sessions have an associated lifetime that requires re-authentication upon expiration. During re-authentication, Samba receives updated group membership information but fails to reflect these changes in subsequent SMB request processing. This occurs due to a recent change in Samba's cache system that maintains associations between user impersonation information and connected shares (Openwall).

Impact

The vulnerability prevents group membership changes from taking effect until users disconnect and establish new connections to the server. This means that when an administrator removes a user from a particular group in Active Directory, the changes are not immediately enforced, potentially allowing users to retain access to resources they should no longer have access to (Samba Security).

Mitigation and workarounds

The issue has been fixed in Samba 4.21.6. No workarounds are available for affected versions, making it necessary to upgrade to the patched version. The Samba Team decided not to issue a dedicated security release for this vulnerability (Openwall).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
David EstlickCISO
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
Adam FletcherChief Security Officer
“We know that if Wiz identifies something as critical, it actually is.”
Greg PoniatowskiHead of Threat and Vulnerability Management