Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-9640

Опубликовано: 15 окт. 2025
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

Отчет

This vulnerability is rated Low because its exploitation scope and potential impact are tightly constrained. Technically, the flaw only allows disclosure of uninitialized heap memory fragments, not direct control or corruption of memory. The attacker must already be an authenticated user with write access to files using the vfs_streams_xattr module, significantly reducing the attack surface. The exposed data is non-deterministic and contextually limited—it consists of residual memory content that may or may not contain meaningful information, with no guarantee of retrieving sensitive secrets. Additionally, Samba already cleanses known secret buffers before freeing memory, further lowering the risk of credential or key exposure.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10sambaFix deferred
Red Hat Enterprise Linux 6sambaFix deferred
Red Hat Enterprise Linux 6samba4Fix deferred
Red Hat Enterprise Linux 7sambaFix deferred
Red Hat Enterprise Linux 8sambaFix deferred
Red Hat Enterprise Linux 9sambaFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-908
https://bugzilla.redhat.com/show_bug.cgi?id=2391698samba: vfs_streams_xattr uninitialized memory write possible

EPSS

Процентиль: 23%
0.00077
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
6 месяцев назад

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

CVSS3: 4.3
nvd
6 месяцев назад

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

CVSS3: 4.3
debian
6 месяцев назад

A flaw was found in Samba, in the vfs_streams_xattr module, where unin ...

CVSS3: 4.3
github
6 месяцев назад

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

CVSS3: 4.3
fstec
6 месяцев назад

Уязвимость модуля vfs_streams_xattr пакета программ сетевого взаимодействия Samba, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 23%
0.00077
Низкий

4.3 Medium

CVSS3