vulnti.work

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory con…

Medium CVSS 4.3
CVECVE-2025-9640
First seen2026-08-21 14:16 UTC
Disclosed2025-10-15 13:16 UTC
Last updated2026-08-21 14:16 UTC
Channel statusauto

Summary

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD