Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsSamba 4.21.0, the first stable release in the 4.21 series, arrived on September 2, 2024. Its most consequential security changes were stricter handling of access-list identities that cannot be resolved because a domain controller cannot be reached, and LDAP SASL support over TLS with channel binding. The initial release is not the whole upgrade story: later 4.21 point releases included security fixes and a configuration-specific Active Directory compatibility warning. Before upgrading, check the notes for your exact point release and deployment.
What changed in Samba 4.21.0?
The Samba Team’s Samba 4.21.0 release notes, published September 2, 2024, describe changes to access control, LDAP security, build packaging, and administration tooling. The release date marks the start of the 4.21 series; it does not establish which 4.21 point release is current now.
Access-list lookups now fail closed on a domain-controller communication error
For the valid users, invalid users, read list, and write list settings, Samba now logs an error and fails the tree connect if it cannot resolve a listed user or group because of a communication error with a domain controller. Previously, an unresolved name could be silently skipped.
This is a specific failure-mode change, not a rule that every invalid name automatically blocks access. Its practical effect is that a share connection can fail when Samba cannot contact a domain controller to resolve an identity that appears in one of these settings. Review the entries and confirm domain-controller connectivity before rollout so that a lookup failure does not unexpectedly interrupt share access.
Recommended Free Tools
#1 Best Overall
LDAP SASL binds can use TLS with channel binding
The LDAP server can accept SASL binds using Kerberos or NTLMSSP over TLS, through either LDAPS or STARTTLS. The release notes say configurations that previously needed ldap server require strong auth = allow_sasl_over_tls can likely use the default ldap server require strong auth = yes. If a deployment specifically requires SASL without correct TLS channel bindings, the notes direct administrators to allow_sasl_without_tls_channel_bindings. The older allow_sasl_over_tls setting triggers a warning at Samba startup and in samba-tool testparm.
Samba’s client tools also include the correct channel bindings when using LDAPS. For LDAP client configuration, 4.21 adds starttls and ldaps as values for client ldap sasl wrapping. Because the client TLS implementation changed, administrators need trusted certificates configured through at least one of tls trust system cas, tls ca directories, or tls cafile. Check the complete release notes and local configuration before changing these settings.
Rank #2
Other changes for administrators and packagers
- LDB was reintegrated into the Samba build instead of being offered as a separate standalone tarball. An optional public library route remains for packagers.
- The LDB Modules API Python bindings were removed because they were unused and broken, and the project had not promised a stable API or ABI for them.
- New and expanded features include gMSA management and client tooling, RFC 8070 PKINIT freshness-extension support in the Heimdal KDC, a reworked authentication-policy command structure, and support for key features of AD Domain and Forest Functional Level 2012R2.
- The release also made builds more deterministic and improved redaction of secrets from process listings when command-line secret options are used. The notes caution that a race can leave passwords briefly visible and that command-line secrets are not removed from shell history.
Why the 4.21 point release matters
Installing the initial 4.21.0 release and installing a later 4.21 maintenance release are not equivalent choices. Later release notes document security fixes and an interoperability issue tied to a particular domain-member configuration.
Samba 4.21.6: CVE-2025-0620
In its 4.21.6 release notes, dated June 3, 2025, the Samba Team documented a fix for CVE-2025-0620. The defect meant smbd did not pick up changed group membership when reauthenticating an expired SMB session.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Samba 4.21.7: Netlogon compatibility warning
The 4.21.7 release notes, dated July 7, 2025, warned that an upcoming Microsoft AD DC Netlogon RPC access-check change would affect Samba domain-member servers using the ad idmapping backend. Treat this as a configuration-specific interoperability concern; the note does not identify all Samba deployments as affected.
Later security announcements and maintenance status
On October 15, 2025, the Samba Team’s security announcement naming 4.21.9 listed it alongside 4.22.5 and 4.23.2 as a release addressing CVE-2025-9640 and CVE-2025-10230.
Rank #4
A planned security update announcement by Samba release manager Björn Jacke on April 2, 2026, was followed by an April 8 postponement notice because an issue had been identified with one fix. These notices establish a plan and its postponement, not a completed release or the latest 4.21 point version. Check Samba’s current release and security information before deciding which version to deploy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to assess an upgrade for your deployment
Use the 4.21 changes that match your configuration to guide testing. An upgrade decision should account for the exact point release as well as the initial series changes.
- Shares with access-list settings: inspect
valid users,invalid users,read list, andwrite list, and test identity resolution while domain controllers are reachable. - LDAP authentication: identify whether clients use SASL over LDAPS or STARTTLS, whether channel bindings are correct, and whether trusted CA certificates are configured for Samba LDAP clients.
- Domain members: check whether the server uses the
adidmapping backend before assessing the Netlogon warning. - Security maintenance: compare the installed 4.21 point version with current release notes and security announcements; do not assume that 4.21.0 or a point version named in an older notice is current.
Test the relevant authentication paths, share connections, and domain-member behavior in a representative environment before production rollout. Use the full release notes for the point release you plan to install, since the 4.21.0 notes alone cannot describe later fixes or compatibility changes.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

