CVE-2022-47941Missing Release of Memory after Effective Lifetime in Kernel

Severity
7.5HIGHNVD
EPSS
2.7%
top 14.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 23

Description

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel5.155.15.61+2
Debianlinux/linux_kernel< 5.19.6-1+2
debiandebian/linux< linux 5.19.6-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2wc2-77r7-4pm8: An issue was discovered in ksmbd in the Linux kernel before 52022-12-23
OSV
CVE-2022-47941: An issue was discovered in ksmbd in the Linux kernel 52022-12-23

📋Vendor Advisories

3
Red Hat
kernel: handling of SMB2_NEGOTIATE command doesn't properly release memory which could result in DoS2022-12-22
Microsoft
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions aka a memory leak.2022-12-13
Debian
CVE-2022-47941: linux - An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5....2022