Memory leak in the VFS file lease handling in locks.c in Linux kernels 2.6.10 to 2.6.15 allows local users to cause a denial of service (memory exhaustion) via certain Samba activities that cause an fasync entry to be re-allocated by the fcntl_setlease function after the fasync queue has already been cleaned by the locks_delete_lock function.
http://www.ubuntulinux.org/usn/usn-231-1
http://www.trustix.org/errata/2005/0070
http://www.securityfocus.com/bid/15745
http://www.securityfocus.com/archive/1/427981/100/0/threaded
http://www.securityfocus.com/archive/1/419522/100/0/threaded
http://www.securityfocus.com/advisories/9806
http://secunia.com/advisories/18203
http://secunia.com/advisories/17918
http://secunia.com/advisories/17917