CVE-2022-49366
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix reference count leak in smb_check_perm_dacl()
The issue happens in a specific path in smb_check_perm_dacl(). When "id" and "uid" have the same value, the function simply jumps out of the loop without decrementing the reference count of the object "posix_acls", which is increased by get_acl() earlier. This may result in memory leaks.
Fix it by decreasing the reference count of "posix_acls" before jumping to label "check_access_bits".
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 777cad1604d68ed4379ec899d1f7d2f6a29f01f0 < cf824b95c12a1abacadbc2d069931963221a3414 | affected |
| Linux | Linux | 777cad1604d68ed4379ec899d1f7d2f6a29f01f0 < 248d71b440aef829f5cc5f6545ca113ef5062900 | affected |
| Linux | Linux | 777cad1604d68ed4379ec899d1f7d2f6a29f01f0 < 9758a6653c27867d810de02b4e5697163dda9883 | affected |
| Linux | Linux | 777cad1604d68ed4379ec899d1f7d2f6a29f01f0 < d21a580dafc69aa04f46e6099616146a536b0724 | affected |
| Linux | Linux | 5.15 | affected |
| Linux | Linux | 0 < 5.15 | unaffected |
| Linux | Linux | 5.15.47 <= 5.15.* | unaffected |
| Linux | Linux | 5.17.15 <= 5.17.* | unaffected |
| Linux | Linux | 5.18.4 <= 5.18.* | unaffected |
| Linux | Linux | 5.19 <= * | unaffected |
Weaknesses
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://git.kernel.org/stable/c/cf824b95c12a1abacadbc2d069931963221a3414
- https://git.kernel.org/stable/c/248d71b440aef829f5cc5f6545ca113ef5062900
- https://git.kernel.org/stable/c/9758a6653c27867d810de02b4e5697163dda9883
- https://git.kernel.org/stable/c/d21a580dafc69aa04f46e6099616146a536b0724
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.