CVE-2023-54076

Linux Kernel 6.4.0-6.4.6 - Use-After-Free in SMB Client Session Reference Counting

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix missed ses refcounting Use new cifs_smb_ses_inc_refcount() helper to get an active reference of @ses and @ses->dfs_root_ses (if set). This will prevent @ses->dfs_root_ses of being put in the next call to cifs_put_smb_ses() and thus potentially causing an use-after-free bug.

Scores

EPSS 0.0016
EPSS Percentile 5.8%

Details

Status published
Products (11)
linux/Kernel 6.4.0 - 6.4.7linux
Linux/Linux < 6.4
Linux/Linux 6.2.15 - 6.3
Linux/Linux 6.3.2 - 6.4
Linux/Linux 6.4
Linux/Linux 6.4.7 - 6.4.*
Linux/Linux 6.5
Linux/Linux 8e3554150d6c80a84b3cb046615d1a0e943811dc - bf99f6be2d20146942bce6f9e90a0ceef12cbc1e
Linux/Linux 8e3554150d6c80a84b3cb046615d1a0e943811dc - eb382196e6f6e05cfafdab797840e5a96c6e7bf0
Linux/Linux c082c3be0f96e759ff2e361d929832fda0b93851
... and 1 more
Published Dec 24, 2025
Tracked Since Feb 18, 2026