Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-49366— ksmbd: fix reference count leak in smb_check_perm_dacl()

AI Predicted 5.5 Difficulty: Trivial EPSS 0.26% · P17

Possible ATT&CK Techniques 1AI

T1496 · Resource Hijacking

Affected Version Matrix 10

VendorProductVersion RangeStatus
LinuxLinux777cad1604d68ed4379ec899d1f7d2f6a29f01f0< cf824b95c12a1abacadbc2d069931963221a3414affected
777cad1604d68ed4379ec899d1f7d2f6a29f01f0< 248d71b440aef829f5cc5f6545ca113ef5062900affected
777cad1604d68ed4379ec899d1f7d2f6a29f01f0< 9758a6653c27867d810de02b4e5697163dda9883affected
777cad1604d68ed4379ec899d1f7d2f6a29f01f0< d21a580dafc69aa04f46e6099616146a536b0724affected
5.15affected
< 5.15unaffected
5.15.47≤ 5.15.*unaffected
5.17.15≤ 5.17.*unaffected
… +2 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-49366

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ksmbd: fix reference count leak in smb_check_perm_dacl()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix reference count leak in smb_check_perm_dacl() The issue happens in a specific path in smb_check_perm_dacl(). When "id" and "uid" have the same value, the function simply jumps out of the loop without decrementing the reference count of the object "posix_acls", which is increased by get_acl() earlier. This may result in memory leaks. Fix it by decreasing the reference count of "posix_acls" before jumping to label "check_access_bits".
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于smb_check_perm_dacl函数在特定路径下未释放posix_acls的引用计数,可能导致内存泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 777cad1604d68ed4379ec899d1f7d2f6a29f01f0 ~ cf824b95c12a1abacadbc2d069931963221a3414 -
LinuxLinux 5.15 -

II. Public POCs for CVE-2022-49366

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-49366

登录查看更多情报信息。

Patches & Fixes for CVE-2022-49366 (4)

Same Patch Batch · Linux · 2025-02-26 · 706 CVEs total

CVE-2022-495619.8 CRITICALnetfilter: conntrack: re-fetch conntrack after insertion
CVE-2022-491499.8 CRITICALrxrpc: Fix call timer start racing with call destruction
CVE-2022-494079.8 CRITICALdlm: fix plock invalid read
CVE-2022-493569.8 CRITICALSUNRPC: Trap RDMA segment overflows
CVE-2022-493629.8 CRITICALNFSD: Fix potential use-after-free in nfsd_file_put()
CVE-2022-492809.8 CRITICALNFSD: prevent underflow in nfssvc_decode_writeargs()
CVE-2022-492609.8 CRITICALcrypto: hisilicon/sec - fix the aead software fallback for engine
CVE-2022-494189.8 CRITICALNFSv4: Fix free of uninitialized nfs4_label on referral lookup.
CVE-2022-492019.8 CRITICALibmvnic: fix race between xmit and reset
CVE-2022-491949.8 CRITICALnet: bcmgenet: Use stronger register read/writes to assure ordering
CVE-2022-490939.8 CRITICALskbuff: fix coalescing for page_pool fragment recycling
CVE-2022-490949.8 CRITICALnet/tls: fix slab-out-of-bounds bug in decrypt_internal
CVE-2022-490589.1 CRITICALcifs: potential buffer overflow in handling symlinks
CVE-2022-494168.8 HIGHwifi: mac80211: fix use-after-free in chanctx code
CVE-2022-495358.8 HIGHscsi: lpfc: Fix null pointer dereference after failing to issue FLOGI and PLOGI
CVE-2022-492388.8 HIGHath11k: free peer for station when disconnect from AP for QCA6390/WCN6855
CVE-2022-495198.8 HIGHath10k: skip ath10k_halt during suspend for driver state RESTARTING
CVE-2022-491388.8 HIGHBluetooth: hci_event: Ignore multiple conn complete events
CVE-2022-494718.8 HIGHrtw89: cfo: check mac_id to avoid out-of-bounds
CVE-2022-491598.8 HIGHscsi: qla2xxx: Implement ref count for SRB

Showing top 20 of 706 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-49366

No comments yet


Leave a comment