Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 92%

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow Commit… (CVE-2026-64139)

0
Medium
Published: 07/19/2026 (07/19/2026, 18:31:53 UTC)
Source: GCVE Database

Description

A memory leak vulnerability in the Linux kernel's ksmbd component was fixed. The issue occurs in the set_posix_acl_entries_dacl() function where an overflow check causes early loop termination but bypasses memory free calls, leaking allocated memory. This leak can be triggered by a malicious or malformed file with many POSIX ACL entries, potentially leading to kernel memory exhaustion. The fix involves freeing allocated memory before breaking out of the loops to prevent the leak.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/19/2026, 19:46:42 UTC

Technical Analysis

The Linux kernel's ksmbd module had a memory leak vulnerability (CVE-2026-64139) in the set_posix_acl_entries_dacl() function. A recent commit introduced overflow checks that break out of loops when the accumulated DACL size would overflow a 16-bit limit. However, these breaks bypass the kfree() calls responsible for releasing allocated struct smb_sid objects, causing a memory leak. An attacker can exploit this by crafting files with enough POSIX ACL entries to trigger the overflow, leaking kernel memory on each access to the file's DACL. The vulnerability allows trivial kernel memory exhaustion. The patch fixes this by ensuring the sid memory is freed before breaking out of the loops.

Potential Impact

The vulnerability allows a local or remote attacker who can cause the kernel to process files with crafted POSIX ACL entries to leak kernel memory repeatedly. This can lead to kernel memory exhaustion, potentially causing denial of service or system instability. There is no indication of privilege escalation or code execution from the provided data.

Mitigation Recommendations

A fix is available and has been applied in the Linux kernel to free the leaked memory before breaking out of the loops. Users should update to the fixed kernel version containing this patch. Since this is not a cloud service, manual patching is required. Patch status is not explicitly confirmed in the input data, so check the vendor advisory for the exact fixed kernel versions and apply updates accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-3c28-w5w6-mh56
Osv Schema Version
1.4.0
Aliases
["CVE-2026-64139"]
Ecosystems
[]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a5d27a82a4a8d598912b22e

Added to database: 07/19/2026, 19:38:16 UTC

Last enriched: 07/19/2026, 19:46:42 UTC

Last updated: 07/20/2026, 17:26:47 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses