Open Source Development

Power Open Source Development

Explore the open source tools and capabilities for building and deploying modern applications on IBM Power platforms including AIX, IBM i, and Linux.


#Power


#Power

 View Only
  • 1.  FIX for "SMB signing is not required" vulnerability

    Posted Tue October 28, 2025 07:13 AM

    Hello All

    I need vulnerable fix for the "SMB signing is not required" on AIX. Please help



    ------------------------------
    goverdhana musunuri
    ------------------------------


  • 2.  RE: FIX for "SMB signing is not required" vulnerability

    Posted Tue October 28, 2025 09:17 AM

    Please be more clear here. What is the CVE and which product is affected by it ? 



    ------------------------------
    Ayappan P
    ------------------------------



  • 3.  RE: FIX for "SMB signing is not required" vulnerability

    Posted Wed October 29, 2025 03:11 AM

    Hi Ayappan

    Samba configured on the AIX 7.2 servers for CIFS mounts. Our scanner not provided any CVE. But, I checked with IBM for remediation for this vulnerability. They mentioned that there is no direct support other than forums.

    Regards

    Goverdhana



    ------------------------------
    goverdhana musunuri
    ------------------------------



  • 4.  RE: FIX for "SMB signing is not required" vulnerability

    Posted Thu October 30, 2025 12:37 AM

    Are you using AIX Toolbox Samba ? It doesn't have CIFS mount capabilities. 



    ------------------------------
    Ayappan P
    ------------------------------



  • 5.  RE: FIX for "SMB signing is not required" vulnerability

    Posted Thu October 30, 2025 10:33 AM

    Talk to your scanner provider.  It's 2025, generic failures aren't acceptable, they must provide something that identifies the actual problem, ideally a CVE or a vendor information page regarding the identified problem.

    In this case, check smb.conf, the global stanza should have:

    client signing = required
    server signing = mandatory



    ------------------------------
    José Pina Coelho
    IT Specialist at Kyndryl
    ------------------------------