This bug was fixed in the package cifs-utils - 2:6.9-1ubuntu0.4
---------------
cifs-utils (2:6.9-1ubuntu0.4) focal-security; urgency=medium
* SECURITY REGRESSION: Fix memory leak in check_service_ticket_exists()
if a valid Kerberos service ticket is not available.
(LP: #2113906)
- d/p/lp2113906-cifs.upcall-fix-memory-leaks-in-check_service_ticket.patch
* SECURITY REGRESSION: Correctly search the calling applications
environment for KRB5CCNAME if running kernel is not patched for
CVE-2025-2312, fixing mounts for AD users. (LP: #2112614)
- d/p/CVE-2025-2312-3.patch: cifs.upcall: correctly treat
UPTARGET_UNSPECIFIED as UPTARGET_APP.
-- Matthew Ruffell <[email protected]> Wed, 11 Jun 2025
16:27:38 +1200
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2113906
Title:
Regression: After LP2099917 cifs.upcall leaks memory on error message
if service ticket doesn't exist
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cifs-utils/+bug/2113906/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs