Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:03604-1

Опубликовано: 15 окт. 2025
Источник: suse-cvrf

Описание

Security update for samba

This update for samba fixes the following issues:

  • CVE-2025-9640: Fixed uninitialized memory disclosure via vfs_streams_xattr (bsc#1251279).
  • CVE-2025-10230: Fixed command Injection in WINS server hook script (bsc#1251280).

Список пакетов

Image SLES12-SP5-Azure-BYOS
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-Azure-HPC-BYOS
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-Azure-HPC-On-Demand
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-Azure-SAP-BYOS
ctdb-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-Azure-SAP-On-Demand
ctdb-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-Azure-Standard-On-Demand
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-EC2-BYOS
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-EC2-ECS-On-Demand
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-EC2-On-Demand
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-EC2-SAP-BYOS
ctdb-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-EC2-SAP-On-Demand
ctdb-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-GCE-BYOS
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-GCE-On-Demand
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-GCE-SAP-BYOS
ctdb-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-GCE-SAP-On-Demand
ctdb-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
ctdb-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
ctdb-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
SUSE Linux Enterprise High Availability Extension 12 SP5
ctdb-4.15.13+git.664.e8416d8d213-3.99.1
SUSE Linux Enterprise Server 12 SP5-LTSS
libsamba-policy-devel-4.15.13+git.664.e8416d8d213-3.99.1
libsamba-policy-python3-devel-4.15.13+git.664.e8416d8d213-3.99.1
libsamba-policy0-python3-4.15.13+git.664.e8416d8d213-3.99.1
libsamba-policy0-python3-32bit-4.15.13+git.664.e8416d8d213-3.99.1
samba-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-32bit-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-libs-32bit-4.15.13+git.664.e8416d8d213-3.99.1
samba-devel-4.15.13+git.664.e8416d8d213-3.99.1
samba-devel-32bit-4.15.13+git.664.e8416d8d213-3.99.1
samba-doc-4.15.13+git.664.e8416d8d213-3.99.1
samba-ldb-ldap-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-32bit-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-python3-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-python3-32bit-4.15.13+git.664.e8416d8d213-3.99.1
samba-python3-4.15.13+git.664.e8416d8d213-3.99.1
samba-tool-4.15.13+git.664.e8416d8d213-3.99.1
samba-winbind-4.15.13+git.664.e8416d8d213-3.99.1
samba-winbind-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-winbind-libs-32bit-4.15.13+git.664.e8416d8d213-3.99.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libsamba-policy-devel-4.15.13+git.664.e8416d8d213-3.99.1
libsamba-policy-python3-devel-4.15.13+git.664.e8416d8d213-3.99.1
libsamba-policy0-python3-4.15.13+git.664.e8416d8d213-3.99.1
libsamba-policy0-python3-32bit-4.15.13+git.664.e8416d8d213-3.99.1
samba-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-32bit-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-client-libs-32bit-4.15.13+git.664.e8416d8d213-3.99.1
samba-devel-4.15.13+git.664.e8416d8d213-3.99.1
samba-devel-32bit-4.15.13+git.664.e8416d8d213-3.99.1
samba-doc-4.15.13+git.664.e8416d8d213-3.99.1
samba-ldb-ldap-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-32bit-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-python3-4.15.13+git.664.e8416d8d213-3.99.1
samba-libs-python3-32bit-4.15.13+git.664.e8416d8d213-3.99.1
samba-python3-4.15.13+git.664.e8416d8d213-3.99.1
samba-tool-4.15.13+git.664.e8416d8d213-3.99.1
samba-winbind-4.15.13+git.664.e8416d8d213-3.99.1
samba-winbind-libs-4.15.13+git.664.e8416d8d213-3.99.1
samba-winbind-libs-32bit-4.15.13+git.664.e8416d8d213-3.99.1

Описание

A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller's wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-Azure-BYOS:samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-Azure-HPC-BYOS:samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-Azure-HPC-BYOS:samba-libs-4.15.13+git.664.e8416d8d213-3.99.1

Ссылки

Описание

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-Azure-BYOS:samba-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-Azure-HPC-BYOS:samba-client-libs-4.15.13+git.664.e8416d8d213-3.99.1
Image SLES12-SP5-Azure-HPC-BYOS:samba-libs-4.15.13+git.664.e8416d8d213-3.99.1

Ссылки