U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-49366

Change History

New CVE Received from kernel.org 2/26/2025 2:01:13 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix reference count leak in smb_check_perm_dacl()

The issue happens in a specific path in smb_check_perm_dacl(). When
"id" and "uid" have the same value, the function simply jumps out of
the loop without decrementing the reference count of the object
"posix_acls", which is increased by get_acl() earlier. This may
result in memory leaks.

Fix it by decreasing the reference count of "posix_acls" before
jumping to label "check_access_bits".
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/248d71b440aef829f5cc5f6545ca113ef5062900
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/9758a6653c27867d810de02b4e5697163dda9883
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/cf824b95c12a1abacadbc2d069931963221a3414
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/d21a580dafc69aa04f46e6099616146a536b0724