Samba 4.25.0 has been released with experimental SMB3 Persistent Handles, enabling eligible clients to reconnect to open files after server restarts, outages, or transparent-failover events without losing their handles. The capability improves service continuity for SMB deployments but incurs a significant performance overhead because Samba records open, update, lease, and close operations twice.
The release also introduces vfs_aio_ratelimit and the ratelimitd daemon for centrally managing asynchronous-I/O limits, plus vfs_ceph_rgw to export Ceph Object Gateway buckets through SMB. Samba adds Active Directory cluster functional-level management for rolling upgrades, improves JSON audit logging, changes default domain Kerberos encryption types to AES, and retains legacy AES types needed for interoperability related to Microsoft Windows Kerberos vulnerability CVE-2026-20833.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
The Samba project released stable Samba 4.25, adding experimental SMB3 Persistent Handles for reconnecting clients after outages or restarts, the vfs_aio_ratelimit and vfs_ceph_rgw modules, Active Directory cluster feature-level management, JSON audit-log improvements, and revised Kerberos/domain encryption defaults. Persistent Handles support is intended for transparent failover but has a performance cost from maintaining duplicate state for open, update, lease, and close operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
phoronix.com
Open sourceopennet.me
Open sourceopennet.ru
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.