Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Samba 4.21.0, the first stable release in the 4.21 series, arrived on September 2, 2024. Its most consequential security changes were stricter handling of access-list identities that cannot be resolved because a domain controller cannot be reached, and LDAP SASL support over TLS with channel binding. The initial release is not the whole upgrade story: later 4.21 point releases included security fixes and a configuration-specific Active Directory compatibility warning. Before upgrading, check the notes for your exact point release and deployment.

What changed in Samba 4.21.0?

The Samba Team’s Samba 4.21.0 release notes, published September 2, 2024, describe changes to access control, LDAP security, build packaging, and administration tooling. The release date marks the start of the 4.21 series; it does not establish which 4.21 point release is current now.

Access-list lookups now fail closed on a domain-controller communication error

For the valid users, invalid users, read list, and write list settings, Samba now logs an error and fails the tree connect if it cannot resolve a listed user or group because of a communication error with a domain controller. Previously, an unresolved name could be silently skipped.

This is a specific failure-mode change, not a rule that every invalid name automatically blocks access. Its practical effect is that a share connection can fail when Samba cannot contact a domain controller to resolve an identity that appears in one of these settings. Review the entries and confirm domain-controller connectivity before rollout so that a lookup failure does not unexpectedly interrupt share access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

LDAP SASL binds can use TLS with channel binding

The LDAP server can accept SASL binds using Kerberos or NTLMSSP over TLS, through either LDAPS or STARTTLS. The release notes say configurations that previously needed ldap server require strong auth = allow_sasl_over_tls can likely use the default ldap server require strong auth = yes. If a deployment specifically requires SASL without correct TLS channel bindings, the notes direct administrators to allow_sasl_without_tls_channel_bindings. The older allow_sasl_over_tls setting triggers a warning at Samba startup and in samba-tool testparm.

Samba’s client tools also include the correct channel bindings when using LDAPS. For LDAP client configuration, 4.21 adds starttls and ldaps as values for client ldap sasl wrapping. Because the client TLS implementation changed, administrators need trusted certificates configured through at least one of tls trust system cas, tls ca directories, or tls cafile. Check the complete release notes and local configuration before changing these settings.

Other changes for administrators and packagers

  • LDB was reintegrated into the Samba build instead of being offered as a separate standalone tarball. An optional public library route remains for packagers.
  • The LDB Modules API Python bindings were removed because they were unused and broken, and the project had not promised a stable API or ABI for them.
  • New and expanded features include gMSA management and client tooling, RFC 8070 PKINIT freshness-extension support in the Heimdal KDC, a reworked authentication-policy command structure, and support for key features of AD Domain and Forest Functional Level 2012R2.
  • The release also made builds more deterministic and improved redaction of secrets from process listings when command-line secret options are used. The notes caution that a race can leave passwords briefly visible and that command-line secrets are not removed from shell history.

Why the 4.21 point release matters

Installing the initial 4.21.0 release and installing a later 4.21 maintenance release are not equivalent choices. Later release notes document security fixes and an interoperability issue tied to a particular domain-member configuration.

Samba 4.21.6: CVE-2025-0620

In its 4.21.6 release notes, dated June 3, 2025, the Samba Team documented a fix for CVE-2025-0620. The defect meant smbd did not pick up changed group membership when reauthenticating an expired SMB session.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Samba 4.21.7: Netlogon compatibility warning

The 4.21.7 release notes, dated July 7, 2025, warned that an upcoming Microsoft AD DC Netlogon RPC access-check change would affect Samba domain-member servers using the ad idmapping backend. Treat this as a configuration-specific interoperability concern; the note does not identify all Samba deployments as affected.

Later security announcements and maintenance status

On October 15, 2025, the Samba Team’s security announcement naming 4.21.9 listed it alongside 4.22.5 and 4.23.2 as a release addressing CVE-2025-9640 and CVE-2025-10230.

A planned security update announcement by Samba release manager Björn Jacke on April 2, 2026, was followed by an April 8 postponement notice because an issue had been identified with one fix. These notices establish a plan and its postponement, not a completed release or the latest 4.21 point version. Check Samba’s current release and security information before deciding which version to deploy.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to assess an upgrade for your deployment

Use the 4.21 changes that match your configuration to guide testing. An upgrade decision should account for the exact point release as well as the initial series changes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Shares with access-list settings: inspect valid users, invalid users, read list, and write list, and test identity resolution while domain controllers are reachable.
  • LDAP authentication: identify whether clients use SASL over LDAPS or STARTTLS, whether channel bindings are correct, and whether trusted CA certificates are configured for Samba LDAP clients.
  • Domain members: check whether the server uses the ad idmapping backend before assessing the Netlogon warning.
  • Security maintenance: compare the installed 4.21 point version with current release notes and security announcements; do not assume that 4.21.0 or a point version named in an older notice is current.

Test the relevant authentication paths, share connections, and domain-member behavior in a representative environment before production rollout. Use the full release notes for the point release you plan to install, since the 4.21.0 notes alone cannot describe later fixes or compatibility changes.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.