CVE-2022-49938

Source
https://cve.org/CVERecord?id=CVE-2022-49938
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49938.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49938
Downstream
Related
Published
2025-06-18T10:54:39.458Z
Modified
2026-03-20T12:24:48.245512Z
Summary
cifs: fix small mempool leak in SMB2_negotiate()
Details

In the Linux kernel, the following vulnerability has been resolved:

cifs: fix small mempool leak in SMB2_negotiate()

In some cases of failure (dialect mismatches) in SMB2negotiate(), after the request is sent, the checks would return -EIO when they should be rather setting rc = -EIO and jumping to negexit to free the response buffer from mempool.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49938.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9764c02fcbad40001fd3f63558d918e4d519bb75
Fixed
9e3c9efa7caf16e5acc05eab5e4d0a714e1610b0
Fixed
38a6b469bf22f153282fbe7d702a24e9eb43f50e
Fixed
27893dfc1285f80f80f46b3b8c95f5d15d2e66d0
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
1ae6f05d4204d3a128bb9ba2c42e2a6c4ac687f1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49938.json"