CVE-2023-54280 (GCVE-0-2023-54280)
Vulnerability from cvelistv5
Published
2025-12-30 12:23
Modified
2026-08-05 09:18
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential race when tree connecting ipc Protect access of TCP_Server_Info::hostname when building the ipc tree name as it might get freed in cifsd thread and thus causing an use-after-free bug in __tree_connect_dfs_target(). Also, while at it, update status of IPC tcon on success and then avoid any extra tree connects.
Impacted products
Vendor Product Version
Linux Linux Version: c88f7dcd6d6429197fc2fd87b54a894ffcd48e8e
Version: c88f7dcd6d6429197fc2fd87b54a894ffcd48e8e
Version: c88f7dcd6d6429197fc2fd87b54a894ffcd48e8e
Version: 81d583baa5f1abd73c755ce1992929debd20b687
Version: 5.15.81   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/cifs/dfs.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "536ec71ba060a02fabe8e22cecb82fe7b3a8708b",
              "status": "affected",
              "version": "c88f7dcd6d6429197fc2fd87b54a894ffcd48e8e",
              "versionType": "git"
            },
            {
              "lessThan": "553476df55a111e6a66ad9155256aec0ec1b7ad0",
              "status": "affected",
              "version": "c88f7dcd6d6429197fc2fd87b54a894ffcd48e8e",
              "versionType": "git"
            },
            {
              "lessThan": "ee20d7c6100752eaf2409d783f4f1449c29ea33d",
              "status": "affected",
              "version": "c88f7dcd6d6429197fc2fd87b54a894ffcd48e8e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "81d583baa5f1abd73c755ce1992929debd20b687",
              "versionType": "git"
            },
            {
              "lessThan": "5.16",
              "status": "affected",
              "version": "5.15.81",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/cifs/dfs.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.16"
            },
            {
              "lessThan": "5.16",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.2.*",
              "status": "unaffected",
              "version": "6.2.15",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.3.*",
              "status": "unaffected",
              "version": "6.3.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.2.15",
                  "versionStartIncluding": "5.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.3.2",
                  "versionStartIncluding": "5.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.4",
                  "versionStartIncluding": "5.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.15.81",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix potential race when tree connecting ipc\n\nProtect access of TCP_Server_Info::hostname when building the ipc tree\nname as it might get freed in cifsd thread and thus causing an\nuse-after-free bug in __tree_connect_dfs_target().  Also, while at it,\nupdate status of IPC tcon on success and then avoid any extra tree\nconnects."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The race is in the CIFS/SMB client\u0027s DFS reconnect path and is driven entirely by remote peer behaviour \u2014 a malicious or compromised SMB/DFS server (or an on-path attacker resetting the TCP session) controls when reconnects occur and which failover targets are returned, and the leaked heap bytes are sent back to that server in the TREE_CONNECT request. Both racing threads (cifsd demux thread and the cifsiod reconnect worker) run automatically over the network connection with no local component.\nAC:L - The attacker controls both sides of the race: dropping the TCP connection forces cifsd into reconnect_dfs_server()/__reconnect_target_unlocked() which kfree()s server-\u003ehostname, while the referral target list it supplies guarantees the free happens, and the cifsiod reconnect worker concurrently reads the pointer unlocked. reconnect_dfs_server() retries in a msleep(3000) loop so the window can be hit repeatedly until it lands.\nPR:N - The attacker acts as the SMB/DFS server or as a network attacker on the connection and never authenticates to or holds any account on the victim host. The vulnerable reconnect path runs in kernel threads (cifsd and the cifsiod reconnect worker), so no privileged or unprivileged local process is needed at all.\nUI:N - Against an already-mounted DFS share \u2014 the normal persistent state for enterprise fstab/autofs mounts \u2014 the entire trigger sequence is kernel-internal: cifsd drops and re-establishes the connection and queues smb2_reconnect_server(), which reaches __tree_connect_dfs_target() with no user process and no victim action.\nS:U - The use-after-free is confined to kernel heap memory of the affected host and does not cross a virtualization, IOMMU, or sandbox boundary. Impact and vulnerable component share the same security authority.\nC:H - The freed hostname buffer is formatted with \"%s\", and string_nocheck() runs with precision -1 (`while (lim--)`), so it reads freed and reallocated heap memory unbounded until a NUL byte, copying up to ~500 bytes into the tree name, which is then transmitted to the remote attacker-controlled server in the SMB2 TREE_CONNECT request \u2014 a direct kernel heap disclosure primitive.\nI:H - This is a use-after-free on an attacker-influenced heap object; an attacker who grooms the reallocated kmalloc chunk controls the string used to build the IPC$ tree-connect request, steering the client\u0027s connection state, and UAF conditions on the CIFS server/session objects are generally leverageable for stronger corruption primitives.\nA:H - The unbounded scan for a NUL over the freed allocation readily walks off the slab object into unmapped memory, producing a kernel oops/panic (and an immediate KASAN BUG on hardened kernels). The remote attacker can retrigger the reconnect race repeatedly until the client crashes."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T09:18:52.296Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/536ec71ba060a02fabe8e22cecb82fe7b3a8708b"
        },
        {
          "url": "https://git.kernel.org/stable/c/553476df55a111e6a66ad9155256aec0ec1b7ad0"
        },
        {
          "url": "https://git.kernel.org/stable/c/ee20d7c6100752eaf2409d783f4f1449c29ea33d"
        }
      ],
      "title": "cifs: fix potential race when tree connecting ipc",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2023-54280",
    "datePublished": "2025-12-30T12:23:22.335Z",
    "dateReserved": "2025-12-30T12:06:44.525Z",
    "dateUpdated": "2026-08-05T09:18:52.296Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…