CVE-2022-50372
published 2025-09-17CVE-2022-50372: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory leak when build ntlmssp negotiate blob failed There is a memory leak when…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.17%
6.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix memory leak when build ntlmssp negotiate blob failed
There is a memory leak when mount cifs:
unreferenced object 0xffff888166059600 (size 448):
comm "mount.cifs", pid 51391, jiffies 4295596373 (age 330.596s)
hex dump (first 32 bytes):
fe 53 4d 42 40 00 00 00 00 00 00 00 01 00 82 00 .SMB@...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[] mempool_alloc+0xe1/0x260
[] cifs_small_buf_get+0x24/0x60
[] __smb2_plain_req_init+0x32/0x460
[] SMB2_sess_alloc_buffer+0xa4/0x3f0
[] SMB2_sess_auth_rawntlmssp_negotiate+0xf5/0x480
[] SMB2_sess_setup+0x253/0x410
[] cifs_setup_session+0x18f/0x4c0
[] cifs_get_smb_ses+0xae7/0x13c0
[] mount_get_conns+0x7a/0x730
[] cifs_mount+0x103/0xd10
[] cifs_smb3_do_mount+0x1dd/0xc90
[] smb3_get_tree+0x1d5/0x300
[] vfs_get_tree+0x41/0xf0
[] path_mount+0x9b3/0xdd0
[] __x64_sys_mount+0x190/0x1d0
[] do_syscall_64+0x35/0x80
When build ntlmssp negotiate blob failed, the session setup request
should be freed.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.6-1 (bookworm) | linux 6.0.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 49bd49f983b5026e4557d31c5d737d9657c4113e < fa5a70bdd5e565c8696fb04dfe18a4e8aff4695d | fa5a70bdd5e565c8696fb04dfe18a4e8aff4695d |
| linux | linux | >= 49bd49f983b5026e4557d31c5d737d9657c4113e < 30b2d7f8f13664655480d6af45f60270b3eb6736 | 30b2d7f8f13664655480d6af45f60270b3eb6736 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.0.6-1 | 6.0.6-1 |
| linux | linux_kernel | >= 0 < 6.0.6-1 | 6.0.6-1 |
| linux | linux_kernel | >= 0 < 6.0.6-1 | 6.0.6-1 |
| linux | linux_kernel | >= 5.16 < 6.0.6 | 6.0.6 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: cifs: Fix memory leak when build ntlmssp negotiate blob failed
vendor_redhat·2025-09-17·CVSS 5.5
CVE-2022-50372 [MEDIUM] CWE-772 kernel: cifs: Fix memory leak when build ntlmssp negotiate blob failed
kernel: cifs: Fix memory leak when build ntlmssp negotiate blob failed
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix memory leak when build ntlmssp negotiate blob failed
There is a memory leak when mount cifs:
unreferenced object 0xffff888166059600 (size 448):
comm "mount.cifs", pid 51391, jiffies 4295596373 (age 330.596s)
hex dump (first 32 bytes):
fe 53 4d 42 40 00 00 00 00 00 00 00 01 00 82 00 .SMB@...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[] mempool_alloc+0xe1/0x260
[] cifs_small_buf_get+0x24/0x60
[] __smb2_plain_req_init+0x32/0x460
[] SMB2_sess_alloc_buffer+0xa4/0x3f0
[] SMB2_sess_auth_rawntlmssp_negotiate+0xf5/0x480
[] SMB2_sess_setup+0x253/0x410
[] cifs_setup_session+0x18f/0x4c0
[] cifs_get_smb_ses+0xae7/
Debian
CVE-2022-50372: linux - In the Linux kernel, the following vulnerability has been resolved: cifs: Fix m...
vendor_debian·2022·CVSS 5.5
CVE-2022-50372 [MEDIUM] CVE-2022-50372: linux - In the Linux kernel, the following vulnerability has been resolved: cifs: Fix m...
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory leak when build ntlmssp negotiate blob failed There is a memory leak when mount cifs: unreferenced object 0xffff888166059600 (size 448): comm "mount.cifs", pid 51391, jiffies 4295596373 (age 330.596s) hex dump (first 32 bytes): fe 53 4d 42 40 00 00 00 00 00 00 00 01 00 82 00 .SMB@........... 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] mempool_alloc+0xe1/0x260 [] cifs_small_buf_get+0x24/0x60 [] __smb2_plain_req_init+0x32/0x460 [] SMB2_sess_alloc_buffer+0xa4/0x3f0 [] SMB2_sess_auth_rawntlmssp_negotiate+0xf5/0x480 [] SMB2_sess_setup+0x253/0x410 [] cifs_setup_session+0x18f/0x4c0 [] cifs_get_smb_ses+0xae7/0x13c0 [] mount_get_conns+0x7a/0x730 [] cifs_mount+0x103/0xd10 [] cifs_s
GHSA
GHSA-5wx2-vv79-wfg8: In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix memory leak when build ntlmssp negotiate blob failed
There is a memory
ghsa_unreviewed·2025-09-17
CVE-2022-50372 [MEDIUM] CWE-401 GHSA-5wx2-vv79-wfg8: In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix memory leak when build ntlmssp negotiate blob failed
There is a memory
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix memory leak when build ntlmssp negotiate blob failed
There is a memory leak when mount cifs:
unreferenced object 0xffff888166059600 (size 448):
comm "mount.cifs", pid 51391, jiffies 4295596373 (age 330.596s)
hex dump (first 32 bytes):
fe 53 4d 42 40 00 00 00 00 00 00 00 01 00 82 00 .SMB@...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[] mempool_alloc+0xe1/0x260
[] cifs_small_buf_get+0x24/0x60
[] __smb2_plain_req_init+0x32/0x460
[] SMB2_sess_alloc_buffer+0xa4/0x3f0
[] SMB2_sess_auth_rawntlmssp_negotiate+0xf5/0x480
[] SMB2_sess_setup+0x253/0x410
[] cifs_setup_session+0x18f/0x4c0
[] cifs_get_smb_ses+0xae7/0x13c0
[] mount_get_conns+0x7a/0x730
[] cifs_mount+0x103/0xd10
[] cifs
OSV
CVE-2022-50372: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory leak when build ntlmssp negotiate blob failed There is a memory l
osv·2025-09-17·CVSS 5.5
CVE-2022-50372 [MEDIUM] CVE-2022-50372: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory leak when build ntlmssp negotiate blob failed There is a memory l
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory leak when build ntlmssp negotiate blob failed There is a memory leak when mount cifs: unreferenced object 0xffff888166059600 (size 448): comm "mount.cifs", pid 51391, jiffies 4295596373 (age 330.596s) hex dump (first 32 bytes): fe 53 4d 42 40 00 00 00 00 00 00 00 01 00 82 00 .SMB@........... 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] mempool_alloc+0xe1/0x260 [] cifs_small_buf_get+0x24/0x60 [] __smb2_plain_req_init+0x32/0x460 [] SMB2_sess_alloc_buffer+0xa4/0x3f0 [] SMB2_sess_auth_rawntlmssp_negotiate+0xf5/0x480 [] SMB2_sess_setup+0x253/0x410 [] cifs_setup_session+0x18f/0x4c0 [] cifs_get_smb_ses+0xae7/0x13c0 [] mount_get_conns+0x7a/0x730 [] cifs_mount+0x103/0xd10 [] cifs_s
No detection rules found.
No public exploits indexed.
2025-09-17
Published