CVE-2025-9640: Samba: vfs_streams_xattr uninitialized memory write possible
Published Aug 29, 2025
·Updated
A flaw was found in Samba
Affected Software
1 affected component
Samba Samba
Event History
Aug 29, 2025
Data Sourced
via Red Hat·03:12 AM
DescriptionSeverityAffected Software
Oct 15, 2025
CVE Published
via MITRE·12:47 PM
Data Sourced
via MITRE·12:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Feb 28, 57989
Event
via FIRST·07:06 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-9640?
CVE-2025-9640 is classified as a medium severity vulnerability due to its potential for information disclosure.
2
How do I fix CVE-2025-9640?
To fix CVE-2025-9640, update to the latest version of Samba that addresses this vulnerability.
3
Who is affected by CVE-2025-9640?
CVE-2025-9640 affects systems running the Samba vfs_streams_xattr module.
4
What type of vulnerability is CVE-2025-9640?
CVE-2025-9640 is an information disclosure vulnerability caused by uninitialized heap memory in Samba.
5
Can CVE-2025-9640 be exploited remotely?
CVE-2025-9640 requires authentication, meaning it cannot be exploited remotely without valid user credentials.