In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix reference count leak in smb_check_perm_dacl()
The issue happens in a specific path in smb_check_perm_dacl(). When "id" and "uid" have the same value, the function simply jumps out of the loop without decrementing the reference count of the object "posix_acls", which is increased by get_acl() earlier. This may result in memory leaks.
Fix it by decreasing the reference count of "posix_acls" before jumping to label "check_access_bits".
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-lowlatency-hwe-5.15Upgrade linux-awsUpgrade linux-azureUpgrade linuxUpgrade linux-hwe-5.15Upgrade linux-raspiUpgrade linux-intel-iotg-5.15Upgrade linux-riscv-5.15Upgrade linux-aws-5.15Upgrade linux-gkeopUpgrade linux-azure-5.15Upgrade linux-lowlatencyUpgrade linux-oracleUpgrade linux-oracle-5.15Upgrade linux-gkeUpgrade linux-nvidiaUpgrade linux-realtimeUpgrade linux-intel-iotgUpgrade linux-ibmUpgrade linux-kvmUpgrade linux-gcpUpgrade linux-gcp-5.15 | Mar 19, 2025 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub