CVE-2025-68219 — Missing Release of Resource after Effective Lifetime in Linux
Severity
7.2HIGHOSV
OSV3.2
No vectorEPSS
0.0%
top 90.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
cifs: fix memory leak in smb3_fs_context_parse_param error path
Add proper cleanup of ctx->source and fc->source to the
cifs_parse_mount_err error handler. This ensures that memory allocated
for the source strings is correctly freed on all error paths, matching
the cleanup already performed in the success path by
smb3_cleanup_fs_context_contents().
Pointers are also set to NULL after freeing to prevent potential
double-free is…
Affected Packages6 packages
▶CVEListV5linux/linux24e0a1eff9e2b9835a6e7c17039dfb6ecfd81f1f — 7627864dc3121f39e220f5253a227edf472de59e+4