cbcvebase.
CVE-2022-50372
published 2025-09-17

CVE-2022-50372: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory leak when build ntlmssp negotiate blob failed There is a memory leak when…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.17%
6.4th percentile
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory leak when build ntlmssp negotiate blob failed There is a memory leak when mount cifs: unreferenced object 0xffff888166059600 (size 448): comm "mount.cifs", pid 51391, jiffies 4295596373 (age 330.596s) hex dump (first 32 bytes): fe 53 4d 42 40 00 00 00 00 00 00 00 01 00 82 00 .SMB@........... 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] mempool_alloc+0xe1/0x260 [] cifs_small_buf_get+0x24/0x60 [] __smb2_plain_req_init+0x32/0x460 [] SMB2_sess_alloc_buffer+0xa4/0x3f0 [] SMB2_sess_auth_rawntlmssp_negotiate+0xf5/0x480 [] SMB2_sess_setup+0x253/0x410 [] cifs_setup_session+0x18f/0x4c0 [] cifs_get_smb_ses+0xae7/0x13c0 [] mount_get_conns+0x7a/0x730 [] cifs_mount+0x103/0xd10 [] cifs_smb3_do_mount+0x1dd/0xc90 [] smb3_get_tree+0x1d5/0x300 [] vfs_get_tree+0x41/0xf0 [] path_mount+0x9b3/0xdd0 [] __x64_sys_mount+0x190/0x1d0 [] do_syscall_64+0x35/0x80 When build ntlmssp negotiate blob failed, the session setup request should be freed.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.6-1 (bookworm)linux 6.0.6-1 (bookworm)
linuxlinux
linuxlinux>= 49bd49f983b5026e4557d31c5d737d9657c4113e < fa5a70bdd5e565c8696fb04dfe18a4e8aff4695dfa5a70bdd5e565c8696fb04dfe18a4e8aff4695d
linuxlinux>= 49bd49f983b5026e4557d31c5d737d9657c4113e < 30b2d7f8f13664655480d6af45f60270b3eb673630b2d7f8f13664655480d6af45f60270b3eb6736
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.0.6-16.0.6-1
linuxlinux_kernel>= 0 < 6.0.6-16.0.6-1
linuxlinux_kernel>= 0 < 6.0.6-16.0.6-1
linuxlinux_kernel>= 5.16 < 6.0.66.0.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.