cbcvebase.
CVE-2025-9640
published 2025-10-15

CVE-2025-9640: A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an…

PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.43%
35.3th percentile
A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiansamba< samba 2:4.17.12+dfsg-0+deb12u3 (bookworm)samba 2:4.17.12+dfsg-0+deb12u3 (bookworm)
sambasamba>= 0 < 2:4.13.13+dfsg-1~deb11u72:4.13.13+dfsg-1~deb11u7
sambasamba>= 0 < 2:4.17.12+dfsg-0+deb12u32:4.17.12+dfsg-0+deb12u3
sambasamba>= 0 < 2:4.22.6+dfsg-0+deb13u12:4.22.6+dfsg-0+deb13u1
sambasamba>= 0 < 2:4.23.2+dfsg-12:4.23.2+dfsg-1
sambasamba>= 0 < 2:4.15.13+dfsg-0ubuntu1.102:4.15.13+dfsg-0ubuntu1.10
sambasamba>= 0 < 2:4.19.5+dfsg-4ubuntu9.42:4.19.5+dfsg-4ubuntu9.4
sambasamba>= 0 < 2:4.22.3+dfsg-4ubuntu2.12:4.22.3+dfsg-4ubuntu2.1
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm152:4.3.11+dfsg-0ubuntu0.14.04.20+esm15
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.34+esm42:4.3.11+dfsg-0ubuntu0.16.04.34+esm4
sambasamba>= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm32:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm3
sambasamba>= 0 < 2:4.15.13+dfsg-0ubuntu0.20.04.8+esm12:4.15.13+dfsg-0ubuntu0.20.04.8+esm1

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.