Home

Description

In the Linux kernel, the following vulnerability has been resolved: cifs: fix memory leak in smb3_fs_context_parse_param error path Add proper cleanup of ctx->source and fc->source to the cifs_parse_mount_err error handler. This ensures that memory allocated for the source strings is correctly freed on all error paths, matching the cleanup already performed in the success path by smb3_cleanup_fs_context_contents(). Pointers are also set to NULL after freeing to prevent potential double-free issues. This change fixes a memory leak originally detected by syzbot. The leak occurred when processing Opt_source mount options if an error happened after ctx->source and fc->source were successfully allocated but before the function completed. The specific leak sequence was: 1. ctx->source = smb3_fs_context_fullpath(ctx, '/') allocates memory 2. fc->source = kstrdup(ctx->source, GFP_KERNEL) allocates more memory 3. A subsequent error jumps to cifs_parse_mount_err 4. The old error handler freed passwords but not the source strings, causing the memory to leak. This issue was not addressed by commit e8c73eb7db0a ("cifs: client: fix memory leak in smb3_fs_context_parse_param"), which only fixed leaks from repeated fsconfig() calls but not this error path. Patch updated with minor change suggested by kernel test robot

PUBLISHED Reserved 2025-12-16 | Published 2025-12-16 | Updated 2025-12-16 | Assigner Linux

Product status

Default status
unaffected

24e0a1eff9e2b9835a6e7c17039dfb6ecfd81f1f (git) before 7627864dc3121f39e220f5253a227edf472de59e
affected

24e0a1eff9e2b9835a6e7c17039dfb6ecfd81f1f (git) before 48d69290270891f988e72edddd9688c20515421d
affected

24e0a1eff9e2b9835a6e7c17039dfb6ecfd81f1f (git) before 37010021d7e0341bb241ca00bcbae31f2c50b23f
affected

24e0a1eff9e2b9835a6e7c17039dfb6ecfd81f1f (git) before 7e4d9120cfa413dd34f4f434befc5dbe6c38b2e5
affected

Default status
affected

5.11
affected

Any version before 5.11
unaffected

6.6.118 (semver)
unaffected

6.12.60 (semver)
unaffected

6.17.10 (semver)
unaffected

6.18 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/7627864dc3121f39e220f5253a227edf472de59e

git.kernel.org/...c/48d69290270891f988e72edddd9688c20515421d

git.kernel.org/...c/37010021d7e0341bb241ca00bcbae31f2c50b23f

git.kernel.org/...c/7e4d9120cfa413dd34f4f434befc5dbe6c38b2e5

cve.org (CVE-2025-68219)

nvd.nist.gov (CVE-2025-68219)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.