File _patchinfo of Package patchinfo.41070

<patchinfo incident="41070">
  <issue tracker="cve" id="2025-9640"/>
  <issue tracker="cve" id="2025-10230"/>
  <issue tracker="bnc" id="1251279">VUL-0: EMBARGOED: CVE-2025-9640: samba: uninitialized memory disclosure via vfs_streams_xattr</issue>
  <issue tracker="bnc" id="1251280">VUL-0: EMBARGOED: CVE-2025-10230: samba: Command injection via WINS server hook script</issue>
  <packager>npower</packager>
  <rating>critical</rating>
  <category>security</category>
  <summary>Security update for samba</summary>
  <description>This update for samba fixes the following issues:

- CVE-2025-9640: Fixed uninitialized memory disclosure via vfs_streams_xattr (bsc#1251279).
- CVE-2025-10230: Fixed command Injection in WINS server hook script (bsc#1251280).
</description>
</patchinfo>
openSUSE Build Service is sponsored by