CVE-2025-68295: smb: client: fix memory leak in cifs_construct_tcon()

Published Dec 16, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix memory leak in cifsconstructtcon()

When having a multiuser mount with domain= specified and using cifscreds, cifssetcifscreds() will end up setting @ctx->domainname, so it needs to be freed before leaving cifsconstructtcon().

This fixes the following memory leak reported by kmemleak:

mount.cifs //srv/share /mnt -o domain=ZELDA,multiuser,... su - testuser cifscreds add -d ZELDA -u testuser ... ls /mnt/1 ... umount /mnt echo scan > /sys/kernel/debug/kmemleak cat /sys/kernel/debug/kmemleak unreferenced object 0xffff8881203c3f08 (size 8): comm "ls", pid 5060, jiffies 4307222943 hex dump (first 8 bytes): 5a 45 4c 44 41 00 cc cc ZELDA... backtrace (crc d109a8cf): kmallocnodetrackcallernoprof+0x572/0x710 kstrdup+0x3a/0x70 cifssbtlink+0x1209/0x1770 [cifs] cifsgetfattr+0xe1/0xf50 [cifs] cifsgetinodeinfo+0xb5/0x240 [cifs] cifsrevalidatedentryattr+0x2d1/0x470 [cifs] cifsgetattr+0x28e/0x450 [cifs] vfsgetattrnosec+0x126/0x180 vfsstatx+0xf6/0x220 dostatx+0xab/0x110 x64sysstatx+0xd5/0x130 dosyscall64+0xbb/0x380 entrySYSCALL64afterhwframe+0x77/0x7f

Affected Software

2 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.117.1-1

Event History

Dec 16, 2025
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
Description
Data Sourced
via NVD·04:16 PM
Description
Dec 18, 2025
Data Sourced
via Microsoft·01:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:02 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2025-68295?

CVE-2025-68295 is classified as a moderate severity vulnerability due to the potential memory leak issue.

2

How do I fix CVE-2025-68295?

To fix CVE-2025-68295, ensure that your Linux kernel is updated to the patched version that addresses the memory leak in cifs_construct_tcon().

3

Which Linux kernel versions are affected by CVE-2025-68295?

CVE-2025-68295 affects specific versions of the Linux kernel that implement the CIFS (Common Internet File System) protocol.

4

What impact does CVE-2025-68295 have on system performance?

The memory leak associated with CVE-2025-68295 can lead to increased memory consumption, potentially degrading system performance over time.

5

Is it safe to use multiuser mounts in Linux with CVE-2025-68295?

Using multiuser mounts in Linux may expose systems to risks associated with CVE-2025-68295 until the vulnerability is patched.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203