Business information leak In linux

Description

A memory and information leak vulnerability was found in the Linux kernel's CIFS/SMB3 filesystem driver. When smb3_reconfigure() fails during smb3_sync_session_ctx_passwords(), the newly allocated password buffers (new_password and new_password2) are not freed or securely erased. This causes a memory leak and leaves sensitive password data in kernel memory that could potentially be exposed.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions