CVE-2025-9640
BaseFortify
Publication date: 2025-10-15
Last updated on: 2025-11-26
Assigner: Red Hat, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samba | samba | 4.22.5 |
| samba | samba | 4.21.9 |
| samba | samba | * |
| samba | samba | 4.23.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-908 | The product uses or accesses a resource that has not been initialized. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Samba's vfs_streams_xattr module involves uninitialized heap memory being written into alternate data streams. An authenticated user can exploit this flaw to read leftover memory content, which may contain sensitive information, leading to an information disclosure issue. [1]
How can this vulnerability impact me? :
The vulnerability allows an authenticated user to access residual memory content that might include sensitive data. This can result in unauthorized disclosure of information, potentially compromising confidentiality within systems running Samba. [1]