CVE-2025-9640Use of Uninitialized Resource in Samba

Severity
4.3MEDIUMNVD
OSV10.0
EPSS
0.1%
top 77.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 15
Latest updateOct 20

Description

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

debiandebian/samba< samba 2:4.17.12+dfsg-0+deb12u3 (bookworm)
Debiansamba/samba< 2:4.13.13+dfsg-1~deb11u7+3
Ubuntusamba/samba< 2:4.15.13+dfsg-0ubuntu1.10+6

🔴Vulnerability Details

4
OSV
samba vulnerabilities2025-10-20
OSV
samba vulnerabilities2025-10-16
OSV
CVE-2025-9640: A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams2025-10-15
GHSA
GHSA-w497-wqwx-v847: A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams2025-10-15

📋Vendor Advisories

4
Ubuntu
Samba vulnerabilities2025-10-20
Ubuntu
Samba vulnerabilities2025-10-16
Red Hat
samba: vfs_streams_xattr uninitialized memory write possible2025-10-15
Debian
CVE-2025-9640: samba - A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized ...2025