SB2025103112 - Memory leak in Linux kernel smb client
Published: October 31, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2025-40103)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the get_smb2_acl_by_path() and set_smb2_acl() functions in fs/smb/client/smb2ops.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/790282abe9d805f08618c1c24ea2529e7259b692
- https://git.kernel.org/stable/c/896bb31e1416f582503db1350cf1bd10dc64e5a6
- https://git.kernel.org/stable/c/c2b77f42205ef485a647f62082c442c1cd69d3fc
- https://git.kernel.org/stable/c/d7dd034c14928306db1b46be277ae439b84dacf9
- https://git.kernel.org/stable/c/e15605b68b490186da2ad8029c0351a9cfb0b9af