In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow Commit… (CVE-2026-64139)
A memory leak vulnerability in the Linux kernel's ksmbd component was fixed. The issue occurs in the set_posix_acl_entries_dacl() function where an overflow check causes early loop termination but bypasses memory free calls, leaking allocated memory. This leak can be triggered by a malicious or malformed file with many POSIX ACL entries, potentially leading to kernel memory exhaustion. The fix involves freeing allocated memory before breaking out of the loops to prevent the leak.
AI Analysis
Technical Summary
The Linux kernel's ksmbd module had a memory leak vulnerability (CVE-2026-64139) in the set_posix_acl_entries_dacl() function. A recent commit introduced overflow checks that break out of loops when the accumulated DACL size would overflow a 16-bit limit. However, these breaks bypass the kfree() calls responsible for releasing allocated struct smb_sid objects, causing a memory leak. An attacker can exploit this by crafting files with enough POSIX ACL entries to trigger the overflow, leaking kernel memory on each access to the file's DACL. The vulnerability allows trivial kernel memory exhaustion. The patch fixes this by ensuring the sid memory is freed before breaking out of the loops.
Potential Impact
The vulnerability allows a local or remote attacker who can cause the kernel to process files with crafted POSIX ACL entries to leak kernel memory repeatedly. This can lead to kernel memory exhaustion, potentially causing denial of service or system instability. There is no indication of privilege escalation or code execution from the provided data.
Mitigation Recommendations
A fix is available and has been applied in the Linux kernel to free the leaked memory before breaking out of the loops. Users should update to the fixed kernel version containing this patch. Since this is not a cloud service, manual patching is required. Patch status is not explicitly confirmed in the input data, so check the vendor advisory for the exact fixed kernel versions and apply updates accordingly.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow Commit… (CVE-2026-64139)
Description
A memory leak vulnerability in the Linux kernel's ksmbd component was fixed. The issue occurs in the set_posix_acl_entries_dacl() function where an overflow check causes early loop termination but bypasses memory free calls, leaking allocated memory. This leak can be triggered by a malicious or malformed file with many POSIX ACL entries, potentially leading to kernel memory exhaustion. The fix involves freeing allocated memory before breaking out of the loops to prevent the leak.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's ksmbd module had a memory leak vulnerability (CVE-2026-64139) in the set_posix_acl_entries_dacl() function. A recent commit introduced overflow checks that break out of loops when the accumulated DACL size would overflow a 16-bit limit. However, these breaks bypass the kfree() calls responsible for releasing allocated struct smb_sid objects, causing a memory leak. An attacker can exploit this by crafting files with enough POSIX ACL entries to trigger the overflow, leaking kernel memory on each access to the file's DACL. The vulnerability allows trivial kernel memory exhaustion. The patch fixes this by ensuring the sid memory is freed before breaking out of the loops.
Potential Impact
The vulnerability allows a local or remote attacker who can cause the kernel to process files with crafted POSIX ACL entries to leak kernel memory repeatedly. This can lead to kernel memory exhaustion, potentially causing denial of service or system instability. There is no indication of privilege escalation or code execution from the provided data.
Mitigation Recommendations
A fix is available and has been applied in the Linux kernel to free the leaked memory before breaking out of the loops. Users should update to the fixed kernel version containing this patch. Since this is not a cloud service, manual patching is required. Patch status is not explicitly confirmed in the input data, so check the vendor advisory for the exact fixed kernel versions and apply updates accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-3c28-w5w6-mh56
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64139"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5d27a82a4a8d598912b22e
Added to database: 07/19/2026, 19:38:16 UTC
Last enriched: 07/19/2026, 19:46:42 UTC
Last updated: 07/20/2026, 17:26:47 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.