Executive brief
Samba, a widely used software suite for file and print sharing between Linux and Windows systems, contains a vulnerability in its handling of extended file attributes. An authenticated user could exploit this flaw to read sensitive information from the server's memory that they should not have access to. This could lead to the exposure of residual data from other system processes or user sessions.
Technical details
A flaw was found in the Samba vfs_streams_xattr module (CWE-908). The vulnerability occurs when uninitialized heap memory is written into alternate data streams (ADS). An authenticated attacker with network access to a Samba share can exploit this to read residual memory content. This residual data may contain sensitive information from previous operations or other processes. The issue is addressed in Samba versions 4.21.9, 4.22.5, and 4.23.2.
Affected products
- Samba Samba < 4.21.9, 4.22.0 < 4.22.5, 4.23.0 < 4.23.2
Timeline
- 2025-08-29: other: Initial bug report in Red Hat Bugzilla
- 2025-10-15: disclosed: Public disclosure of the vulnerability
- 2026-05-26: patched: Security releases 4.24.3, 4.23.8, and 4.22.10 made available
References
- https://www.samba.org/
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/security/cve/CVE-2025-9640
- https://bugzilla.redhat.com/show_bug.cgi?id=2391698
- https://www.samba.org/samba/history/security.html
- http://www.openwall.com/lists/oss-security/2025/10/15/2
- http://www.openwall.com/lists/oss-security/2025/10/16/2