Impact
The vulnerability is a kernel‑level memory leak in the Linux SMB server; the ksmbd_ipc_login_request_ext() function returns a buffer that the code fails to free until after ksmbd_alloc_user() runs, leaving a dangling object detectable by kmemleak. The leaked object contains partially initialized data that could expose sensitive kernel memory contents. The flaw is a data exposure issue and does not provide a direct path to remote code execution. Based on the description, it is inferred that a process running with sufficient privileges could read the leaked object and access kernel memory that was not intended to be exposed.
Affected Systems
All Linux kernel releases that include the SMB server component prior to the commit that added the missing free operation are affected. This encompasses the standard kernel packages distributed by major Linux vendors, any kernel that matches the CPE for Linux kernel and contains the SMB server code. No specific version numbers are supplied in the advisory, so all kernels that incorporate the vulnerable SMB server are considered vulnerable.
Risk and Exploitability
The EPSS score is reported as < 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The likely attack vector is interaction with the SMB service, but no explicit attack pattern is provided in the advisory; based on the description, it is inferred that conditions that trigger the leak involve SMB traffic to the server. The impact is limited to information disclosure; there is no direct privilege escalation or remote code execution. For systems that do not expose SMB services or that restrict SMB traffic to trusted hosts, the overall risk is low.
OpenCVE Enrichment
Debian DLA
Debian DSA