ZeroHour

CVE-2022-50372

CVSS 3.1
5.5 medium
EPSS
<1%p8
Published
()
Modified
Description

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory leak when build ntlmssp negotiate blob failed There is a memory leak when mount cifs: unreferenced object 0xffff888166059600 (size 448): comm "mount.cifs", pid 51391, jiffies 4295596373 (age 330.596s) hex dump (first 32 bytes): fe 53 4d 42 40 00 00 00 00 00 00 00 01 00 82 00 .SMB@........... 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [ ] mempool_alloc+0xe1/0x260 [ ] cifs_small_buf_get+0x24/0x60 [ ] __smb2_plain_req_init+0x32/0x460 [ ] SMB2_sess_alloc_buffer+0xa4/0x3f0 [ ] SMB2_sess_auth_rawntlmssp_negotiate+0xf5/0x480 [ ] SMB2_sess_setup+0x253/0x410 [ ] cifs_setup_session+0x18f/0x4c0 [ ] cifs_get_smb_ses+0xae7/0x13c0 [ ] mount_get_conns+0x7a/0x730 [ ] cifs_mount+0x103/0xd10 [ ] cifs_smb3_do_mount+0x1dd/0xc90 [ ] smb3_get_tree+0x1d5/0x300 [ ] vfs_get_tree+0x41/0xf0 [ ] path_mount+0x9b3/0xdd0 [ ] __x64_sys_mount+0x190/0x1d0 [ ] do_syscall_64+0x35/0x80 When build ntlmssp negotiate blob failed, the session setup request should be freed.

Vendors
linux
Products
linux kernel
Weakness
CWE-401
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.