CVE-2023-53794 (GCVE-0-2023-53794)
Vulnerability from cvelistv5
Published
2025-12-09 00:00
Modified
2026-08-05 09:16
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: cifs: fix session state check in reconnect to avoid use-after-free issue Don't collect exiting session in smb2_reconnect_server(), because it will be released soon. Note that the exiting session will stay in server->smb_ses_list until it complete the cifs_free_ipc() and logoff() and then delete itself from the list.
Impacted products
Vendor Product Version
Linux Linux Version: 4fcd1813e6404dd4420c7d12fb483f9320f0bf93
Version: 4fcd1813e6404dd4420c7d12fb483f9320f0bf93
Version: 4fcd1813e6404dd4420c7d12fb483f9320f0bf93
Version: 655e0c067f0e02ece03fd0591dabe3db2ae27552
Version: 875cc09c0767a4ac06b57af383709657f98b3ea1
Version: 599fe1409085059ba12a2c3897c853be9fa9e7cf
Version: 2e4378ee60049b752c9dce16f62ce6fbd11b379a
Version: 59b520454b323ec43b2ae757217332cea33091e0
Version: e20c888e2b3576e5f498c167729d274ef60b86f8
Version: 4ce7aa4e44d88ce64ea8ae2337b8910f3670b0ba
Version: 419fad68e4c4135ff9859e9214dd6cf954413ca1
Version: 3.10.103   
Version: 3.12.63   
Version: 3.14.74   
Version: 3.16.37   
Version: 3.18.37   
Version: 4.1.28   
Version: 4.4.16   
Version: 4.6.5   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/smb2pdu.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "7e4f5c3f01fb0e51ca438e43262d858daf9a0a76",
              "status": "affected",
              "version": "4fcd1813e6404dd4420c7d12fb483f9320f0bf93",
              "versionType": "git"
            },
            {
              "lessThan": "759ffc164d95a32c09528766d74d9b4fb054e8f4",
              "status": "affected",
              "version": "4fcd1813e6404dd4420c7d12fb483f9320f0bf93",
              "versionType": "git"
            },
            {
              "lessThan": "99f280700b4cc02d5f141b8d15f8e9fad0418f65",
              "status": "affected",
              "version": "4fcd1813e6404dd4420c7d12fb483f9320f0bf93",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "655e0c067f0e02ece03fd0591dabe3db2ae27552",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "875cc09c0767a4ac06b57af383709657f98b3ea1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "599fe1409085059ba12a2c3897c853be9fa9e7cf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2e4378ee60049b752c9dce16f62ce6fbd11b379a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "59b520454b323ec43b2ae757217332cea33091e0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e20c888e2b3576e5f498c167729d274ef60b86f8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4ce7aa4e44d88ce64ea8ae2337b8910f3670b0ba",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "419fad68e4c4135ff9859e9214dd6cf954413ca1",
              "versionType": "git"
            },
            {
              "lessThan": "3.11",
              "status": "affected",
              "version": "3.10.103",
              "versionType": "semver"
            },
            {
              "lessThan": "3.13",
              "status": "affected",
              "version": "3.12.63",
              "versionType": "semver"
            },
            {
              "lessThan": "3.15",
              "status": "affected",
              "version": "3.14.74",
              "versionType": "semver"
            },
            {
              "lessThan": "3.17",
              "status": "affected",
              "version": "3.16.37",
              "versionType": "semver"
            },
            {
              "lessThan": "3.19",
              "status": "affected",
              "version": "3.18.37",
              "versionType": "semver"
            },
            {
              "lessThan": "4.2",
              "status": "affected",
              "version": "4.1.28",
              "versionType": "semver"
            },
            {
              "lessThan": "4.5",
              "status": "affected",
              "version": "4.4.16",
              "versionType": "semver"
            },
            {
              "lessThan": "4.7",
              "status": "affected",
              "version": "4.6.5",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/smb2pdu.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.7"
            },
            {
              "lessThan": "4.7",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.47",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.4.*",
              "status": "unaffected",
              "version": "6.4.12",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.5",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.47",
                  "versionStartIncluding": "4.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.4.12",
                  "versionStartIncluding": "4.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.5",
                  "versionStartIncluding": "4.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.10.103",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.12.63",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.14.74",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.16.37",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.18.37",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.1.28",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.4.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.6.5",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix session state check in reconnect to avoid use-after-free issue\n\nDon\u0027t collect exiting session in smb2_reconnect_server(), because it\nwill be released soon.\n\nNote that the exiting session will stay in server-\u003esmb_ses_list until\nit complete the cifs_free_ipc() and logoff() and then delete itself\nfrom the list."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable code is the SMB/CIFS client\u0027s reconnect worker, whose execution and timing are dictated entirely by a remote SMB peer (TCP resets, malformed PDUs, STATUS_NETWORK_SESSION_EXPIRED, stalled SMB2_LOGOFF replies, DFS referrals). A malicious/compromised file server or an on-path attacker triggers it purely over TCP/445 with no local access.\nAC:L - The attacker controls both sides of the race: it stalls the SMB2_LOGOFF response to hold the session in SES_EXITING on smb_ses_list for the full response timeout, while forcing smb2_reconnect_server() to run on demand and repeatedly (it also self-requeues every 2 seconds), making the window trivially wide and the hit near-certain.\nPR:N - No credentials or privileges on the victim system are required \u2014 the attacker is the remote server (or an on-path attacker) acting against an existing mount, and the triggering conditions are protocol-level responses that require no authenticated privilege on the client.\nUI:N - Against an already-established mount (fstab, autofs, systemd automount, container share) the attack proceeds with no victim action; the session teardown side is generated by normal client activity such as DFS referral handling and session churn that the attacker itself induces.\nS:U - The freed and reused objects (struct cifs_ses, struct cifs_tcon) and the resulting corruption all live within the kernel\u0027s own security authority, with no crossing into a hypervisor, IOMMU, or other security scope.\nC:H - A use-after-free on a heap-allocated cifs_ses/cifs_tcon lets the attacker groom the freed slab and have the reconnect path read session fields (Suid, auth_key.response, chans[], dfs_root_ses) out of attacker-influenced memory, yielding a kernel information-disclosure primitive.\nI:H - The worker writes into the freed objects \u2014 list_add_tail() stores two pointers into ses-\u003erlist and the freed tcon_ipc-\u003erlist, ses_count is incremented through a dangling dfs_root_ses pointer, and cifs_setup_session() writes ses_status/Suid and frees ses-\u003eauth_key.response \u2014 giving write and controlled-free primitives usable for control-flow hijack.\nA:H - The use-after-free reliably corrupts kernel memory, taking spinlocks and mutexes inside a freed allocation and corrupting list heads, which oopses or panics the machine and can hang the cifs workqueue."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T09:16:01.824Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7e4f5c3f01fb0e51ca438e43262d858daf9a0a76"
        },
        {
          "url": "https://git.kernel.org/stable/c/759ffc164d95a32c09528766d74d9b4fb054e8f4"
        },
        {
          "url": "https://git.kernel.org/stable/c/99f280700b4cc02d5f141b8d15f8e9fad0418f65"
        }
      ],
      "title": "cifs: fix session state check in reconnect to avoid use-after-free issue",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2023-53794",
    "datePublished": "2025-12-09T00:00:51.061Z",
    "dateReserved": "2025-12-08T23:58:35.274Z",
    "dateUpdated": "2026-08-05T09:16:01.824Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…