CVE-2025-39929
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path
CVSS
7.5
High
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Published: Oct 4, 2025 · Last modified: Jul 30, 2026 · CWE-401
0.3%EPSS · 30 days0.3%
2026-08-132026-09-09
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path During tests of another unrelated patch I was able to trigger this error: Objects remaining on __kmem_cache_shutdown()
- git.kernel.orghttps://git.kernel.org/stable/c/0991418bf98f191d0c320bd25245fcffa1998c7e
- git.kernel.orghttps://git.kernel.org/stable/c/3d7c075c878ac844e33c43e506c2fa27ac7e9689
- git.kernel.orghttps://git.kernel.org/stable/c/5aa69aabcb275a8012265233c7694076ce1d9102
- git.kernel.orghttps://git.kernel.org/stable/c/922338efaad63cfe30d459dfc59f9d69ff93ded4
- git.kernel.orghttps://git.kernel.org/stable/c/aa4cf7615328eae44f3b4bf5f4fde3fb390c27c6
- git.kernel.orghttps://git.kernel.org/stable/c/daac51c7032036a0ca5f1aa419ad1b0471d1c6e0
- git.kernel.orghttps://git.kernel.org/stable/c/e7b7a93879558e77d950f1ff9a6f3daa385b33df
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/html/ssa-082556.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-781313.7 LOW—
———strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.9hCVE-2026-781273.7 LOW—
———libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.9hCVE-2026-781243.7 LOW—
———strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.9hCVE-2026-700657.5 HIG66.3%
——20Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.18hCVE-2026-698097.5 HIG63.7%
——19Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network.3dCVE-2026-697816.5 MED42.3%
——13Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.17h