Back

MEDIUM

ksmbd: fix reference count leak in smb_check_perm_dacl()

Published Feb 26, 2025

Description

The issue happens in a specific path in smb_check_perm_dacl(). When "id" and "uid" have the same value, the function simply jumps out of the loop without decrementing the reference count of the object "posix_acls", which is increased by get_acl() earlier. This may result in memory leaks.

Fix it by decreasing the reference count of "posix_acls" before jumping to label "check_access_bits".

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Feb 26, 2025
Updated May 11, 2026
Reserved Feb 26, 2025
CISA Vulnrichment
Updated Oct 1, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 26, 2025