-

CVE-2023-53794

In the Linux kernel, the following vulnerability has been resolved:

cifs: fix session state check in reconnect to avoid use-after-free issue

Don't collect exiting session in smb2_reconnect_server(), because it
will be released soon.

Note that the exiting session will stay in server->smb_ses_list until
it complete the cifs_free_ipc() and logoff() and then delete itself
from the list.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < 7e4f5c3f01fb0e51ca438e43262d858daf9a0a76
Version 4fcd1813e6404dd4420c7d12fb483f9320f0bf93
Status affected
Version < 759ffc164d95a32c09528766d74d9b4fb054e8f4
Version 4fcd1813e6404dd4420c7d12fb483f9320f0bf93
Status affected
Version < 99f280700b4cc02d5f141b8d15f8e9fad0418f65
Version 4fcd1813e6404dd4420c7d12fb483f9320f0bf93
Status affected
Version 655e0c067f0e02ece03fd0591dabe3db2ae27552
Status affected
Version 875cc09c0767a4ac06b57af383709657f98b3ea1
Status affected
Version 599fe1409085059ba12a2c3897c853be9fa9e7cf
Status affected
Version 2e4378ee60049b752c9dce16f62ce6fbd11b379a
Status affected
Version 59b520454b323ec43b2ae757217332cea33091e0
Status affected
Version e20c888e2b3576e5f498c167729d274ef60b86f8
Status affected
Version 4ce7aa4e44d88ce64ea8ae2337b8910f3670b0ba
Status affected
Version 419fad68e4c4135ff9859e9214dd6cf954413ca1
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.7
Status affected
Version < 4.7
Version 0
Status unaffected
Version <= 6.1.*
Version 6.1.47
Status unaffected
Version <= 6.4.*
Version 6.4.12
Status unaffected
Version <= *
Version 6.5
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.057
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.