-

CVE-2023-53358

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix racy issue under cocurrent smb2 tree disconnect

There is UAF issue under cocurrent smb2 tree disconnect.
This patch introduce TREE_CONN_EXPIRE flags for tcon to avoid cocurrent
access.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < b36295c17fb97424406f0c3ab321b1ccaabb9be8
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < bd80d35725a0cf4df9307bfe2f1a3b2cb983d8e6
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < dc1c17716c099c90948ebb83e2170dd75a3be6b6
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 39366b47a59d46af15ac57beb0996268bf911f6a
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 30210947a343b6b3ca13adc9bfc88e1543e16dd5
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 5.15
Status affected
Version < 5.15
Version 0
Status unaffected
Version <= 5.15.*
Version 5.15.145
Status unaffected
Version <= 6.1.*
Version 6.1.28
Status unaffected
Version <= 6.2.*
Version 6.2.15
Status unaffected
Version <= 6.3.*
Version 6.3.2
Status unaffected
Version <= *
Version 6.4
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.119
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string