SB2025120844 - Memory leak in Linux kernel smb server
Published: December 8, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2025-40286)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the smb2_read() function in fs/smb/server/smb2pdu.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0797c6cf3b857cc229ab2bc69552938dcd738d78
- https://git.kernel.org/stable/c/63d8706a2c09a0c29b8b0e8a44bc7a1339685de9
- https://git.kernel.org/stable/c/6fced056d2cc8d01b326e6fcfabaacb9850b71a4
- https://git.kernel.org/stable/c/bfda5422a16651d0bf864ec468b1c216e1b10d91
- https://git.kernel.org/stable/c/f1305587731886da37a214cda812ade246c653b0