CVE-2025-40286 — Missing Release of Memory after Effective Lifetime in Linux
33 documents7 sources
Severity
3.2LOWOSV
No vectorEPSS
0.1%
top 84.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 6
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
smb/server: fix possible memory leak in smb2_read()
Memory leak occurs when ksmbd_vfs_read() fails.
Fix this by adding the missing kvfree().
Affected Packages7 packages
▶CVEListV5linux/linuxe2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 — 0797c6cf3b857cc229ab2bc69552938dcd738d78+5