CVE-2023-54280

Linux Kernel 5.16-6.2.14, 6.3.0-6.3.1 - Use-After-Free in CIFS Tree Connect

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential race when tree connecting ipc Protect access of TCP_Server_Info::hostname when building the ipc tree name as it might get freed in cifsd thread and thus causing an use-after-free bug in __tree_connect_dfs_target(). Also, while at it, update status of IPC tcon on success and then avoid any extra tree connects.

Scores

EPSS 0.0017
EPSS Percentile 7.0%

Details

Status published
Products (12)
linux/Kernel 5.16.0 - 6.2.15linux
linux/Kernel 6.3.0 - 6.3.2linux
Linux/Linux < 5.16
Linux/Linux 5.15.81 - 5.16
Linux/Linux 5.16
Linux/Linux 6.2.15 - 6.2.*
Linux/Linux 6.3.2 - 6.3.*
Linux/Linux 6.4
Linux/Linux 81d583baa5f1abd73c755ce1992929debd20b687
Linux/Linux c88f7dcd6d6429197fc2fd87b54a894ffcd48e8e - 536ec71ba060a02fabe8e22cecb82fe7b3a8708b
... and 2 more
Published Dec 30, 2025
Tracked Since Feb 18, 2026