Linux Kernel CIFS SMB2 Negotiate Function Memory Leak Vulnerability

Vulnerability

A memory leak vulnerability has been identified in the Linux kernel's CIFS (Common Internet File System) implementation, specifically within the SMB2 negotiate function. This issue arises when the function encounters dialect mismatches and fails to properly manage the response buffer, leading to a small but notable leak in the memory pool.

Impact

The vulnerability causes a minor memory leak, which could accumulate over time and potentially lead to memory exhaustion.

Added: Jun 18, 2025, 10:22 PM
Updated: Jun 18, 2025, 10:22 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.