CVE-2023-54280
Linux Kernel 5.16-6.2.14, 6.3.0-6.3.1 - Use-After-Free in CIFS Tree Connect
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential race when tree connecting ipc Protect access of TCP_Server_Info::hostname when building the ipc tree name as it might get freed in cifsd thread and thus causing an use-after-free bug in __tree_connect_dfs_target(). Also, while at it, update status of IPC tcon on success and then avoid any extra tree connects.
References (3)
Core 3
Scores
EPSS
0.0017
EPSS Percentile
7.0%
Details
Status
published
Products (12)
linux/Kernel
5.16.0 - 6.2.15linux
linux/Kernel
6.3.0 - 6.3.2linux
Linux/Linux
< 5.16
Linux/Linux
5.15.81 - 5.16
Linux/Linux
5.16
Linux/Linux
6.2.15 - 6.2.*
Linux/Linux
6.3.2 - 6.3.*
Linux/Linux
6.4
Linux/Linux
81d583baa5f1abd73c755ce1992929debd20b687
Linux/Linux
c88f7dcd6d6429197fc2fd87b54a894ffcd48e8e - 536ec71ba060a02fabe8e22cecb82fe7b3a8708b
... and 2 more
Published
Dec 30, 2025
Tracked Since
Feb 18, 2026