Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-9640

Опубликовано: 15 окт. 2025
Источник: debian

Описание

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sambafixed2:4.23.2+dfsg-1package
sambafixed2:4.22.6+dfsg-0+deb13u1trixiepackage
sambafixed2:4.17.12+dfsg-0+deb12u3bookwormpackage

Примечания

  • https://www.samba.org/samba/security/CVE-2025-9640.html

  • https://bugzilla.samba.org/show_bug.cgi?id=15885

Связанные уязвимости

CVSS3: 4.3
ubuntu
3 месяца назад

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

CVSS3: 4.3
nvd
3 месяца назад

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

CVSS3: 4.3
github
3 месяца назад

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

CVSS3: 4.3
fstec
3 месяца назад

Уязвимость модуля vfs_streams_xattr пакета программ сетевого взаимодействия Samba, позволяющая нарушителю получить доступ к конфиденциальной информации

suse-cvrf
около 2 месяцев назад

Security update for samba