Missing Release of Resource after Effective Lifetime in Samba - #VU131186
Published: May 12, 2026
Samba
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a file descriptor leak in vfs_glusterfs when handling directory operations over persistent SMB2 connections. A local user can maintain persistent SMB2 connections to cause a denial of service.
The issue results in unbounded memory growth on the GlusterFS brick.