← Πίσω στην αναζήτηση CVE

CVE-2026-64139

Linux Kernel

Περιγραφή

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow Commit 299f962c0b02 (-ksmbd: use check_add_overflow() to prevent u16 DACL size overflow-) added check_add_overflow() guards that break out of the ACE-building loops in set_posix_acl_entries_dacl() when the accumulated DACL size would wrap past 65535. However, each iteration allocates a struct smb_sid via kmalloc_obj() at the top of the loop and relies on the kfree(sid) call at the end of the loop body (the -pass_same_sid- label in the first loop, and the explicit kfree at the tail of the second loop) to release it. The newly introduced -break- statements bypass those kfree() calls, leaking the sid buffer every time an overflow is detected. A malicious or malformed file with enough POSIX ACL entries to trip the overflow check will leak one or more struct smb_sid allocations on every request that touches the file-s DACL, providing a trivial kernel memory exhaustion vector. Free sid before breaking out of the loops to plug the leak.

EPSS 0.184%Κίνδυνος 0
Προβολή πηγής
Δημοσίευση
2026-07-19 16:17:55
Επηρεαζόμενες εκδόσεις
unknown
Τύπος
Πυρήνας
Τελευταία τροποποίηση
2026-07-30 14:59:47
Διάνυσμα
Pending