In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory and information leak in smb3reconfigure() In smb3reconfigure(), if smb3syncsessionctxpasswords() fails, the function returns immediately without freeing and erasing the newly allocated newpassword and newpassword2. This causes both a memory leak and a potential information leak. Fix this by calling kfree_sensitive() on both password buffers before returning in this error case.