Описание
Security update for samba
This update for samba fixes the following issues:
- CVE-2025-9640: Fixed vfs_streams_xattr uninitialized memory write (bsc#1251279).
- CVE-2025-10230: Fixed command Injection in WINS Server Hook Script (bsc#1251280).
Список пакетов
SUSE Enterprise Storage 7.1
SUSE Linux Enterprise High Availability Extension 15 SP3
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
SUSE Linux Enterprise Micro 5.2
SUSE Linux Enterprise Server 15 SP3-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP3
Ссылки
- Link for SUSE-SU-2025:3677-1
- E-Mail link for SUSE-SU-2025:3677-1
- SUSE Security Ratings
- SUSE Bug 1251279
- SUSE Bug 1251280
- SUSE CVE CVE-2025-10230 page
- SUSE CVE CVE-2025-9640 page
Описание
A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller's wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process.
Затронутые продукты
Ссылки
- CVE-2025-10230
- SUSE Bug 1251280
Описание
A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.
Затронутые продукты
Ссылки
- CVE-2025-9640
- SUSE Bug 1251279