CVE-2025-71151

Source
https://cve.org/CVERecord?id=CVE-2025-71151
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71151.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-71151
Downstream
Published
2026-01-23T14:15:17.916Z
Modified
2026-03-20T12:46:39.133119Z
Summary
cifs: Fix memory and information leak in smb3_reconfigure()
Details

In the Linux kernel, the following vulnerability has been resolved:

cifs: Fix memory and information leak in smb3_reconfigure()

In smb3reconfigure(), if smb3syncsessionctxpasswords() fails, the function returns immediately without freeing and erasing the newly allocated newpassword and new_password2. This causes both a memory leak and a potential information leak.

Fix this by calling kfree_sensitive() on both password buffers before returning in this error case.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71151.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
880a661e67648a3ffe85405e8de5f50650a3c0b2
Fixed
bc390b2737205163e48cc1655f6a0c8cd55b02fc
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0e4145774c016530bf99afb3675a1a0593c35642
Fixed
5679cc90bb5415801fa29041da0319d9e15d295d
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0f0e357902957fba28ed31bde0d6921c6bd1485d
Fixed
bb82aaee16907dc4d0b9b0ca7953ceb3edc328c6
Fixed
cb6d5aa9c0f10074f1ad056c3e2278ad2cc7ec8d
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
674ba43944dab8e8f87434e25d9d10c5152584bc

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71151.json"