cbcvebase.
CVE-2025-0620
published 2025-06-06

CVE-2025-0620: A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can…

PriorityP424medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.62%
45.9th percentile
A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.

Affected

5 ranges
VendorProductVersion rangeFixed in
debiansamba< samba 2:4.22.2+dfsg-1 (forky)samba 2:4.22.2+dfsg-1 (forky)
sambasamba>= 0 < 2:4.22.2+dfsg-12:4.22.2+dfsg-1
sambasamba>= 0 < 2:4.22.2+dfsg-12:4.22.2+dfsg-1
sambasamba>= 4.21.0 < 4.21.64.21.6
sambasamba>= 4.22.0 < 4.22.24.22.2

CVSS provenance

nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
osv4.9MEDIUM
vendor_redhat5.1MEDIUM
vendor_debian4.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.