CVE-2025-9640
Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/10/2025
Última modificación:
26/11/2025
Descripción
*** Pendiente de traducción *** A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.
Impacto
Puntuación base 3.x
4.30
Gravedad 3.x
MEDIA
Referencias a soluciones, herramientas e información
- https://access.redhat.com/security/cve/CVE-2025-9640
- https://bugzilla.redhat.com/show_bug.cgi?id=2391698
- https://www.samba.org/samba/history/security.html
- http://www.openwall.com/lists/oss-security/2025/10/15/2
- http://www.openwall.com/lists/oss-security/2025/10/16/2
- https://lists.debian.org/debian-lts-announce/2025/11/msg00027.html



