Samba 4.23.13 ships with seven fixes and a security spine as the 4.22 series retires
Samba Team member Björn Jacke announced 4.23.13 on Thursday, Oct. 1, 2026. It's the latest point release of the 4.23 stable branch, bundling seven bug fixes across file services, SMB3 signing, winbind, CTDB clustering, and Python tooling. One of them closes an out-of-bounds read, which is the kind of flaw you absolutely do not want sitting in a network-facing C daemon.
The timing is the interesting part. On the same day Samba updated its news page, it quietly declared that the 4.22 series has hit end-of-life. That retirement landed just weeks after 4.25.0 dropped on September 24, so the project is effectively running on two tracks right now. Four-point-three stays maintained. Four-two-five is where the new stuff goes.
Keep in mind that this is a maintenance release, not a feature dump. There is nothing flashy here. The value is in the details.
The fixes themselves
The one that pulls the most attention is BUG 15962. SMB3 session-setup responses must now always be signed. It is the clearest security play in the batch, and it follows a pattern Samba has built up over years, echoing the same instinct that disabled SMBv1 by default after the WannaCry outbreaks. (It's fitting that the project's origin story involves a PhD student, Andrew Tridgell, using a packet sniffer to reverse-engineer a DEC server protocol in 1991. Security and interoperability have been a headache from day one.)
BUG 16239 comes from Kopylov Pavel at Cloud Linux, which is a nice example of the upstream-fix model working as intended. The parser for the kdc default domain supported enctypes parameter now handles uppercase "0X" hex correctly. More important, it shuts down an out-of-bounds read triggered by a zero token. Bounds checks on inputs you cannot fully control are exactly where remote exploits begin, so I would flag this one during any security review.
The remaining fixes are stability and correctness work, which is usually the case with these point releases. BUG 16081 stops a winbind crash that appears whenever max domain connections exceeds 1, covering basically every real-world deployment. BUG 16097 makes the POSIX ACL backend stop silently swallowing errors, so access-control failures actually surface instead of vanishing like ghosts. BUG 16240 keeps smbd's temporary directory names within the filesystem's NAME_MAX limit, which otherwise blocks otherwise-valid client names from finishing their work.
Two more bugs land in Samba's clustering layer, which matters if you run high-availability setups. BUG 16258 adds a missing talloc stack frame to the Python smbconf transaction path under CTDB. BUG 16254 stops database operations from being routed to the wrong nodes. A routing bug in a cluster can quietly wreck data consistency, and Martin Schwenke of DDN is the one who fixed it.
Stay on 4.23 or climb to 4.25?
For the sysadmin trying to decide what to install tonight, the answer is pretty clear. 4.23 still gets security backports, so if you are already on it, this release is a ship-it rather than a panic. But 4.22 users need to act. The EOL announcement makes the call blunt. No more security releases there.
If you want the bleeding-edge material, that is 4.25.0. It carries experimental SMB3 Persistent Handles, a building block for Transparent Failover that lets clients reconnect with valid file handles after a server restart. There is also a new CTDB cluster functional level for controlled rolling upgrades. Worth knowing that persistent handles come with a real performance tax, so they are aimed at always-on workloads, not your everyday file share.
Some of the 4.25 fixes overlap with this release. BUG 15962, BUG 16081, and BUG 16239 are already in 4.25.0, which confirms they belong to the broader stable-branch maintenance effort.
Head here for the full release notes and the individual Bugzilla tickets if you want to read the code-level detail.
