CVE-2025-71151
cifs: Fix memory and information leak in smb3_reconfigure()
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory and information leak in smb3_reconfigure() In smb3_reconfigure(), if smb3_sync_session_ctx_passwords() fails, the
function returns immediately without freeing and erasing the newly
allocated new_password and new_password2. This causes both a memory leak
and a potential information leak. Fix this by calling kfree_sensitive() on both password buffers before
returning in this error case.
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory and information leak in smb3_reconfigure() In smb3_reconfigure(), if smb3_sync_session_ctx_passwords() fails, the function returns immediately without freeing and erasing the newly allocated new_password and new_password2. This causes both a memory leak and a potential information leak. Fix this by calling kfree_sensitive() on both password buffers before returning in this error case.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2026-01-13 CVE Reserved
- 2026-01-23 CVE Published
- 2026-01-26 CVE Updated
- 2026-01-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (8)
| URL | Tag | Source |
|---|---|---|
| https://git.kernel.org/stable/c/880a661e67648a3ffe85405e8de5f50650a3c0b2 | Vuln. Introduced | |
| https://git.kernel.org/stable/c/0e4145774c016530bf99afb3675a1a0593c35642 | Vuln. Introduced | |
| https://git.kernel.org/stable/c/0f0e357902957fba28ed31bde0d6921c6bd1485d | Vuln. Introduced | |
| https://git.kernel.org/stable/c/674ba43944dab8e8f87434e25d9d10c5152584bc | Vuln. Introduced |
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.6.64 < 6.6.120 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.6.64 < 6.6.120" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.12.2 < 6.12.64 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.12.2 < 6.12.64" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.13 < 6.18.3 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.13 < 6.18.3" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.13 < 6.19-rc3 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.13 < 6.19-rc3" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 6.11.11 Search vendor "Linux" for product "Linux Kernel" and version "6.11.11" | en |
Affected
| ||||||
