Impact
The vulnerability arises when the SMB client allocates a read request buffer but fails to release it during error paths, resulting in a memory leak. This occurs only in the asynchronous read operation, where an allocation error leads to the buffer being allocated and then never freed. The leaked buffers can accumulate, causing the kernel to exhaust available memory and potentially trigger an out‑of‑memory condition or service disruption. The weakness is a classic resource leak (CWE-401).
Affected Systems
The flaw exists in all Linux kernel versions that have not incorporated the patch identified by a set of commit hashes—including the patch that flushes the buffer during error returns. It is tied specifically to the SMB client read path (smb2_async_readv) and affects any system capable of executing SMB2 read requests, regardless of kernel distribution or release. Users of mainstream Linux distributions whose kernels are older than the one containing this fix remain vulnerable until they apply an updated kernel that includes the mentioned commits.
Risk and Exploitability
The EPSS score is reported to be less than 1 %, indicating a very low likelihood of real‑world exploitation at present. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is flooding SMB read requests designed to trigger memory registration failures, thereby inducing repeated EAGAIN errors that lead to the buffer leak. Because the flaw only manifests under error conditions (memory registration failure) and the SMB client would need to repeatedly trigger those errors, an attacker would need to craft SMB read traffic that causes repeated EAGAIN failures, which could be complex. Nonetheless, the unchecked leak could lead to memory exhaustion, so the risk is moderate if the flaw is triggered frequently. Administrators should treat this as a low‑to‑moderate risk until patched.
OpenCVE Enrichment
Debian DLA
Debian DSA