Andrew Walker discovered that Samba incorrectly initialized memory in the vfs_streams_xattr module. An authenticated attacker could possibly use this issue to obtain sensitive information. (CVE-2025-9640) Igor Morgenstern discovered that Samba incorrectly handled names passed to the WINS hook program. An attacker could possibly use this issue to execute arbitrary code. (CVE-2025-10230)
Continue reading...
Continue reading...

