CVE-2025-9640 Details
Description
A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.
A vulnerability exists in the Samba vfs_streams_xattr module, where uninitialized heap memory can be written into alternate data streams. This flaw allows authenticated users to access residual memory content that may contain sensitive information, leading to unauthorized information disclosure.
Users can upgrade to Samba versions 4.23.2, 4.22.5, or 4.21.9, all of which include the necessary fix for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 15, 2025CISA-ADP
Assessed Oct 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2025/11/msg00027.html | CVE | |
| http://www.openwall.com/lists/oss-security/2025/10/15/2 | CVE | |
| http://www.openwall.com/lists/oss-security/2025/10/16/2 | CVE | |
| https://access.redhat.com/security/cve/CVE-2025-9640 | [email protected] | AdvisoryRemedyVendor |
| https://bugzilla.redhat.com/show_bug.cgi?id=2391698 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://www.samba.org/samba/history/security.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-908 | Use of Uninitialized Resource | CISA-ADP |
| CWE-908 | Use of Uninitialized Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Samba | >= 4.0, < 4.16.11 >= 4.0, < 4.17.10 >= 4.0, < 4.18.5 |
CPE
Remediation
| |
Change History
13 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | CVE |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 21, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 26, 2025 | CVE Modified | CVE |
| Nov 4, 2025 | CVE Modified | CVE |
| Oct 23, 2025 | CVE Modified | [email protected] |
| Oct 15, 2025 | New CVE Received | [email protected] |
| Oct 15, 2025 | CVE Modified | CISA-ADP |
Volerion