CVE-2026-93812

Summary

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr

ndr_encode_v4_ntacl() allocates sd_ndr.data via kzalloc() at entry. If any subsequent ndr_write_*() call returns error during encoding, the allocated sd_ndr.data won't be freed and causes memory leak.

Move kfree(sd_ndr.data) into out label to ensure the buffer gets released on all success and error return paths.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux303fff2b8c77a85c62dbde3b27c24b084144c04c < 9b4dec75498fd0a1c9eaea680aef59c9519eb16faffected
LinuxLinux303fff2b8c77a85c62dbde3b27c24b084144c04c < c521dd78e036b5e0cfd394dd2ff2218890dd9e41affected
LinuxLinux303fff2b8c77a85c62dbde3b27c24b084144c04c < d4d56b00c7df88cd5751e7415bdfabc9fdbc82a7affected
LinuxLinux5.15affected
LinuxLinux0 < 5.15unaffected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References