Memory Leak Vulnerability in Linux Kernel ksmbd by Vendor
CVE-2026-64139

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64139?

A recent vulnerability in the Linux kernel's ksmbd component inadvertently introduces a memory leak during DACL processing. The issue arises in the set_posix_acl_entries_dacl() function, where improper management of SID memory allocations can lead to memory exhaustion on the kernel. When a file has a malformed amount of POSIX ACL entries that trigger an overflow check, it bypasses the necessary memory release processes, thus leaking allocated memory segments. This flaw not only compromises system efficiency but also opens the door for potential denial-of-service attacks when triggered. Proper safeguards have been proposed to ensure that memory is adequately freed before exiting critical sections of the code to mitigate this risk.

Affected Version(s)

Linux 8d5729350b236896f51379588d9a690b7fafb8db < 9d378e17c864da08c3a4df41dae92cfa6468b00a

Linux e1955a94b6f17f4b058afa955a6f187eb3ed7615 < 519fb0a42ce5d7e46935577309fb282a5f2c6ea3

Linux 5e7b8f3c539d69b2ed5f2408e2f75e68ce7eef43 < 0e198f09cb2a554c04de0fea4e790f1250a943ca

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.