# CVE-2025-9640

## Summary

- **CVE ID:** CVE-2025-9640
- **Severity:** MEDIUM
- **CVSS Score:** 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **CWE:** CWE-908
- **Published:** Oct 15, 2025
- **Last Modified:** Sep 1, 2026

## Description

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

## Affected Products

- Unknown product (0)
- Unknown product (4.22.0)
- Unknown product (4.23.0)

## References

- [CNA](https://access.redhat.com/security/cve/CVE-2025-9640)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2391698)
- [CNA](https://www.samba.org/samba/history/security.html)
- [CVE](http://www.openwall.com/lists/oss-security/2025/10/15/2)
- [CVE](http://www.openwall.com/lists/oss-security/2025/10/16/2)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/11/msg00027.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.46%
- **EPSS Percentile:** 39.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._