Impact
A memory leak was detected in the Linux kernel SMB2 client within the smb2_open_file() function, causing the CIFS module to retain cached objects when unloaded. The leak can cause gradual kernel memory depletion, leading to service degradation, crashes, or a panic. This issue is classified as CWE‑401 and has a CVSS score of 5.5, indicating moderate impact. It manifests during typical SMB operations such as mounting a read‑only share, creating a file, unmounting, and removing the module.
Affected Systems
All Linux kernel builds that include the CIFS (CIFS client) module are affected, notably the 6.19 release candidate series up to RC8 and any downstream distributions shipping these kernels. The fix is incorporated in later kernel releases; users should apply updates accordingly.
Risk and Exploitability
The CVSS rating of 5.5 reflects moderate severity, while EPSS is less than 1 % and the vulnerability is not in the CISA KEV catalog, suggesting low exploitation probability. An attacker who can mount an SMB share, perform file operations, and unload the module can trigger the leak, potentially leading to denial of service over time, but not providing arbitrary code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA