<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for samba</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2025:21005-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2025-11-18T22:57:17Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2025-11-18T22:57:17Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-11-18T22:57:17Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for samba</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for samba fixes the following issues:

Update to 4.22.5:

  * CVE-2025-10230: Command injection via WINS server hook script (bsc#1251280).
  * CVE-2025-9640: uninitialized memory disclosure via vfs_streams_xattr (bsc#1251279).

- Relax samba-gpupdate requirement for cepces, certmonger, and sscep
  to a recommends. They are only required if utilizing certificate
  auto enrollment (bsc#1249087).

- Disable timeouts for smb.service so that possibly slow running
  ExecStartPre script 'update-samba-security-profile' doesn't
  cause service start to fail due to timeouts (bsc#1249181).

- Ensure semanage is pulled in as a requirement when samba in
  installed when selinux security access mechanism that is used
  (bsc#1249180).

- don't attempt to label paths that don't exist, also remove
  unecessary evaluation of semange &amp; restorecon cmds (bsc#1249179).

Update to 4.22.4:

  * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with
    SysvolReady=0
  * getpwuid does not shift to new DC when current DC is down
  * Windows security hardening locks out schannel'ed netlogon dc
    calls like netr_DsRGetDCName-
  * Unresponsive second DC can cause idmapping failure when using
    idmap_ad-
  * kinit command is failing with Missing cache Error.
  * Figuring out the DC name from IP address fails and breaks
    fork_domain_child().
  * vfs_streams_depot fstatat broken.
  * Delayed leader broadcast can block ctdb forever.
  * Apparently there is a conflict between shadow_copy2 module
    and virusfilter (action quarantine).
  * Fix handling of empty GPO link.
  * SMB ACL inheritance doesn't work for files created.

- adjust gpgme build dependency for future-proofing

</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-SLES-16.0-22</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2025/suse-su-202521005-1/</URL>
      <Description>Link for SUSE-SU-2025:21005-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2025-November/023386.html</URL>
      <Description>E-Mail link for SUSE-SU-2025:21005-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1249087</URL>
      <Description>SUSE Bug 1249087</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1249179</URL>
      <Description>SUSE Bug 1249179</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1249180</URL>
      <Description>SUSE Bug 1249180</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1249181</URL>
      <Description>SUSE Bug 1249181</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1251279</URL>
      <Description>SUSE Bug 1251279</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1251280</URL>
      <Description>SUSE Bug 1251280</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-10230/</URL>
      <Description>SUSE CVE CVE-2025-10230 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-9640/</URL>
      <Description>SUSE CVE CVE-2025-9640 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 16.0">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 16.0">
        <FullProductName ProductID="SUSE Linux Enterprise Server 16.0" CPE="cpe:/o:suse:sles:16.0">SUSE Linux Enterprise Server 16.0</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 16.0">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0">SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ctdb-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="ctdb-4.22.5+git.431.dc5a539f124-160000.1.1">ctdb-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ctdb-pcp-pmda-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="ctdb-pcp-pmda-4.22.5+git.431.dc5a539f124-160000.1.1">ctdb-pcp-pmda-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ldb-tools-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="ldb-tools-4.22.5+git.431.dc5a539f124-160000.1.1">ldb-tools-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libldb-devel-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="libldb-devel-4.22.5+git.431.dc5a539f124-160000.1.1">libldb-devel-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libldb2-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="libldb2-4.22.5+git.431.dc5a539f124-160000.1.1">libldb2-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-ldb-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="python3-ldb-4.22.5+git.431.dc5a539f124-160000.1.1">python3-ldb-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-4.22.5+git.431.dc5a539f124-160000.1.1">samba-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-ad-dc-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-ad-dc-4.22.5+git.431.dc5a539f124-160000.1.1">samba-ad-dc-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-ad-dc-libs-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-ad-dc-libs-4.22.5+git.431.dc5a539f124-160000.1.1">samba-ad-dc-libs-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-client-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-client-4.22.5+git.431.dc5a539f124-160000.1.1">samba-client-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-client-libs-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-client-libs-4.22.5+git.431.dc5a539f124-160000.1.1">samba-client-libs-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-dcerpc-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-dcerpc-4.22.5+git.431.dc5a539f124-160000.1.1">samba-dcerpc-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-devel-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-devel-4.22.5+git.431.dc5a539f124-160000.1.1">samba-devel-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-doc-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-doc-4.22.5+git.431.dc5a539f124-160000.1.1">samba-doc-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-dsdb-modules-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-dsdb-modules-4.22.5+git.431.dc5a539f124-160000.1.1">samba-dsdb-modules-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-gpupdate-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-gpupdate-4.22.5+git.431.dc5a539f124-160000.1.1">samba-gpupdate-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-ldb-ldap-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-ldb-ldap-4.22.5+git.431.dc5a539f124-160000.1.1">samba-ldb-ldap-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-libs-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-libs-4.22.5+git.431.dc5a539f124-160000.1.1">samba-libs-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-libs-python3-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-libs-python3-4.22.5+git.431.dc5a539f124-160000.1.1">samba-libs-python3-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-python3-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-python3-4.22.5+git.431.dc5a539f124-160000.1.1">samba-python3-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-tool-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-tool-4.22.5+git.431.dc5a539f124-160000.1.1">samba-tool-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-winbind-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-winbind-4.22.5+git.431.dc5a539f124-160000.1.1">samba-winbind-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-winbind-libs-4.22.5+git.431.dc5a539f124-160000.1.1">
      <FullProductName ProductID="samba-winbind-libs-4.22.5+git.431.dc5a539f124-160000.1.1">samba-winbind-libs-4.22.5+git.431.dc5a539f124-160000.1.1</FullProductName>
    </Branch>
    <Relationship ProductReference="ctdb-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:ctdb-4.22.5+git.431.dc5a539f124-160000.1.1">ctdb-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="ctdb-pcp-pmda-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:ctdb-pcp-pmda-4.22.5+git.431.dc5a539f124-160000.1.1">ctdb-pcp-pmda-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="ldb-tools-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:ldb-tools-4.22.5+git.431.dc5a539f124-160000.1.1">ldb-tools-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="libldb-devel-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:libldb-devel-4.22.5+git.431.dc5a539f124-160000.1.1">libldb-devel-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="libldb2-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:libldb2-4.22.5+git.431.dc5a539f124-160000.1.1">libldb2-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-ldb-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:python3-ldb-4.22.5+git.431.dc5a539f124-160000.1.1">python3-ldb-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-4.22.5+git.431.dc5a539f124-160000.1.1">samba-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-ad-dc-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-ad-dc-4.22.5+git.431.dc5a539f124-160000.1.1">samba-ad-dc-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-ad-dc-libs-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-ad-dc-libs-4.22.5+git.431.dc5a539f124-160000.1.1">samba-ad-dc-libs-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-client-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-client-4.22.5+git.431.dc5a539f124-160000.1.1">samba-client-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-client-libs-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-client-libs-4.22.5+git.431.dc5a539f124-160000.1.1">samba-client-libs-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-dcerpc-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-dcerpc-4.22.5+git.431.dc5a539f124-160000.1.1">samba-dcerpc-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-devel-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-devel-4.22.5+git.431.dc5a539f124-160000.1.1">samba-devel-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-doc-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-doc-4.22.5+git.431.dc5a539f124-160000.1.1">samba-doc-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-dsdb-modules-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-dsdb-modules-4.22.5+git.431.dc5a539f124-160000.1.1">samba-dsdb-modules-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-gpupdate-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-gpupdate-4.22.5+git.431.dc5a539f124-160000.1.1">samba-gpupdate-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-ldb-ldap-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-ldb-ldap-4.22.5+git.431.dc5a539f124-160000.1.1">samba-ldb-ldap-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-libs-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-libs-4.22.5+git.431.dc5a539f124-160000.1.1">samba-libs-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-libs-python3-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-libs-python3-4.22.5+git.431.dc5a539f124-160000.1.1">samba-libs-python3-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-python3-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-python3-4.22.5+git.431.dc5a539f124-160000.1.1">samba-python3-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-tool-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-tool-4.22.5+git.431.dc5a539f124-160000.1.1">samba-tool-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-winbind-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-winbind-4.22.5+git.431.dc5a539f124-160000.1.1">samba-winbind-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-winbind-libs-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:samba-winbind-libs-4.22.5+git.431.dc5a539f124-160000.1.1">samba-winbind-libs-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="ctdb-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:ctdb-4.22.5+git.431.dc5a539f124-160000.1.1">ctdb-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="ctdb-pcp-pmda-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:ctdb-pcp-pmda-4.22.5+git.431.dc5a539f124-160000.1.1">ctdb-pcp-pmda-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="ldb-tools-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:ldb-tools-4.22.5+git.431.dc5a539f124-160000.1.1">ldb-tools-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="libldb-devel-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:libldb-devel-4.22.5+git.431.dc5a539f124-160000.1.1">libldb-devel-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="libldb2-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:libldb2-4.22.5+git.431.dc5a539f124-160000.1.1">libldb2-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-ldb-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:python3-ldb-4.22.5+git.431.dc5a539f124-160000.1.1">python3-ldb-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-4.22.5+git.431.dc5a539f124-160000.1.1">samba-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-ad-dc-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-ad-dc-4.22.5+git.431.dc5a539f124-160000.1.1">samba-ad-dc-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-ad-dc-libs-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-ad-dc-libs-4.22.5+git.431.dc5a539f124-160000.1.1">samba-ad-dc-libs-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-client-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-client-4.22.5+git.431.dc5a539f124-160000.1.1">samba-client-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-client-libs-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-client-libs-4.22.5+git.431.dc5a539f124-160000.1.1">samba-client-libs-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-dcerpc-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-dcerpc-4.22.5+git.431.dc5a539f124-160000.1.1">samba-dcerpc-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-devel-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-devel-4.22.5+git.431.dc5a539f124-160000.1.1">samba-devel-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-doc-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-doc-4.22.5+git.431.dc5a539f124-160000.1.1">samba-doc-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-dsdb-modules-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-dsdb-modules-4.22.5+git.431.dc5a539f124-160000.1.1">samba-dsdb-modules-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-gpupdate-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-gpupdate-4.22.5+git.431.dc5a539f124-160000.1.1">samba-gpupdate-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-ldb-ldap-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-ldb-ldap-4.22.5+git.431.dc5a539f124-160000.1.1">samba-ldb-ldap-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-libs-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-libs-4.22.5+git.431.dc5a539f124-160000.1.1">samba-libs-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-libs-python3-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-libs-python3-4.22.5+git.431.dc5a539f124-160000.1.1">samba-libs-python3-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-python3-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-python3-4.22.5+git.431.dc5a539f124-160000.1.1">samba-python3-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-tool-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-tool-4.22.5+git.431.dc5a539f124-160000.1.1">samba-tool-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-winbind-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-winbind-4.22.5+git.431.dc5a539f124-160000.1.1">samba-winbind-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-winbind-libs-4.22.5+git.431.dc5a539f124-160000.1.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 16.0:samba-winbind-libs-4.22.5+git.431.dc5a539f124-160000.1.1">samba-winbind-libs-4.22.5+git.431.dc5a539f124-160000.1.1 as a component of SUSE Linux Enterprise Server for SAP Applications 16.0</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller's wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process.</Note>
    </Notes>
    <CVE>CVE-2025-10230</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 16.0:ctdb-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:ctdb-pcp-pmda-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:ldb-tools-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:libldb-devel-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:libldb2-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:python3-ldb-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-ad-dc-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-ad-dc-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-client-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-client-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-dcerpc-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-devel-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-doc-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-dsdb-modules-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-gpupdate-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-ldb-ldap-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-libs-python3-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-python3-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-tool-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-winbind-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-winbind-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:ctdb-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:ctdb-pcp-pmda-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:ldb-tools-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:libldb-devel-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:libldb2-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:python3-ldb-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-ad-dc-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-ad-dc-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-client-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-client-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-dcerpc-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-devel-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-doc-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-dsdb-modules-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-gpupdate-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-ldb-ldap-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-libs-python3-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-python3-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-tool-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-winbind-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-winbind-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2025/suse-su-202521005-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-10230.html</URL>
        <Description>CVE-2025-10230</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1251280</URL>
        <Description>SUSE Bug 1251280</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.</Note>
    </Notes>
    <CVE>CVE-2025-9640</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 16.0:ctdb-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:ctdb-pcp-pmda-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:ldb-tools-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:libldb-devel-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:libldb2-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:python3-ldb-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-ad-dc-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-ad-dc-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-client-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-client-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-dcerpc-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-devel-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-doc-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-dsdb-modules-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-gpupdate-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-ldb-ldap-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-libs-python3-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-python3-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-tool-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-winbind-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:samba-winbind-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:ctdb-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:ctdb-pcp-pmda-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:ldb-tools-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:libldb-devel-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:libldb2-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:python3-ldb-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-ad-dc-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-ad-dc-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-client-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-client-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-dcerpc-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-devel-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-doc-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-dsdb-modules-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-gpupdate-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-ldb-ldap-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-libs-python3-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-python3-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-tool-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-winbind-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 16.0:samba-winbind-libs-4.22.5+git.431.dc5a539f124-160000.1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2025/suse-su-202521005-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-9640.html</URL>
        <Description>CVE-2025-9640</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1251279</URL>
        <Description>SUSE Bug 1251279</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
