gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in...
Low severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Mar 21, 2024
Description
Published by the National Vulnerability Database
May 5, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Mar 21, 2024
gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through 5.6.10 lacks certain domain_release calls, leading to a memory leak.
References