CVE-2025-9640

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.
Configurations

No configuration.

History

15 Oct 2025, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-15 13:16

Updated : 2025-10-23 16:17


NVD link : CVE-2025-9640

Mitre link : CVE-2025-9640

CVE.ORG link : CVE-2025-9640


JSON object : View

Products Affected

No product.

CWE
CWE-908

Use of Uninitialized Resource