CVE-2025-40268
Last modified
CVE-2025-40268 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: cifs: client: fix memory leak in smb3_fs_context_parse_param The user calls fsconfig twice, but when the program exits, free() only frees ctx->source for the second fsconfig, not the first. Regarding fc->source, there is no code in the fs context related to its memory reclamation. To fix this memory leak, release the source memory corresponding to ctx or fc before each parsing. syzbot reported: BUG: memory leak unreferenced object 0xffff888128afa360 (size 96): backtrace (crc 79c9c7ba): kstrdup+0x3c/0x80 mm/util.c:84 smb3_fs_context_parse_param+0x229b/0x36c0 fs/smb/client/fs_context.c:1444 BUG: memory leak unreferenced object 0xffff888112c7d900 (size 96): backtrace (crc 79c9c7ba): smb3_fs_context_fullpath+0x70/0x1b0 fs/smb/client/fs_context.c:629 smb3_fs_context_parse_param+0x2266/0x36c0 fs/smb/client/fs_context.c:1438. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: cifs: client: fix memory leak in smb3_fs_context_parse_param The user calls fsconfig twice, but when the program exits, free() only frees ctx->source for the second fsconfig, not the first. Regarding fc->source, there is no code in the fs context related to its memory reclamation. To fix this memory leak, release the source memory corresponding to ctx or fc before each parsing. syzbot reported: BUG: memory leak unreferenced object 0xffff888128afa360 (size 96): backtrace (crc 79c9c7ba): kstrdup+0x3c/0x80 mm/util.c:84 smb3_fs_context_parse_param+0x229b/0x36c0 fs/smb/client/fs_context.c:1444 BUG: memory leak unreferenced object 0xffff888112c7d900 (size 96): backtrace (crc 79c9c7ba): smb3_fs_context_fullpath+0x70/0x1b0 fs/smb/client/fs_context.c:629 smb3_fs_context_parse_param+0x2266/0x36c0 fs/smb/client/fs_context.c:1438
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= af1a3d2ba9543e99d78914d8fb88b61d0531d9a1, < 868fc62811d3fabcf5685e14f36377a855d5412d; >= af1a3d2ba9543e99d78914d8fb88b61d0531d9a1, < 48c17341577e25a22feb13d694374b61d974edbc; >= af1a3d2ba9543e99d78914d8fb88b61d0531d9a1, < 4515743cc7a42e1d67468402a6420c195532a6fa; >= af1a3d2ba9543e99d78914d8fb88b61d0531d9a1, < e8c73eb7db0a498cd4b22d2819e6ab1a6f506bd6 |
| Linux | Linux | 5.11 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40268?
How severe is CVE-2025-40268?
How do I fix CVE-2025-40268?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-40262In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40263In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40264In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40265In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40266In the Linux kernel, the following vulnerability has been re…8.2
- CVE-2025-40267In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40269In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-4027A vulnerability, which was classified as critical, was found…9.8
- CVE-2025-40270In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40271In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40272In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40273In the Linux kernel, the following vulnerability has been re…8.8
Are you affected by CVE-2025-40268?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
