CVE-2023-54076
Linux Kernel 6.4.0-6.4.6 - Use-After-Free in SMB Client Session Reference Counting
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix missed ses refcounting Use new cifs_smb_ses_inc_refcount() helper to get an active reference of @ses and @ses->dfs_root_ses (if set). This will prevent @ses->dfs_root_ses of being put in the next call to cifs_put_smb_ses() and thus potentially causing an use-after-free bug.
References (2)
Core 2
Scores
EPSS
0.0016
EPSS Percentile
5.8%
Details
Status
published
Products (11)
linux/Kernel
6.4.0 - 6.4.7linux
Linux/Linux
< 6.4
Linux/Linux
6.2.15 - 6.3
Linux/Linux
6.3.2 - 6.4
Linux/Linux
6.4
Linux/Linux
6.4.7 - 6.4.*
Linux/Linux
6.5
Linux/Linux
8e3554150d6c80a84b3cb046615d1a0e943811dc - bf99f6be2d20146942bce6f9e90a0ceef12cbc1e
Linux/Linux
8e3554150d6c80a84b3cb046615d1a0e943811dc - eb382196e6f6e05cfafdab797840e5a96c6e7bf0
Linux/Linux
c082c3be0f96e759ff2e361d929832fda0b93851
... and 1 more
Published
Dec 24, 2025
Tracked Since
Feb 18, 2026