CVE Database
/

CVE-2023-53377

Back to search

CVE-2023-53377

Published: Sep 18, 2025

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: cifs: prevent use-after-free by freeing the cfile later In smb2_compound_op we have a possible use-after-free which can cause hard to debug problems later on. This was revealed during stress testing with KASAN enabled kernel. Fixing it by moving the cfile free call to a few lines below, after the usage.

VendorProductVersions

Linux

Linux

affected
76894f3e2f71177747b8b4763fb180e800279585 - < 4fe07d55a5461e66a55fbefb57f85ff0facea32b
affected
76894f3e2f71177747b8b4763fb180e800279585 - < b6353518ef8180816e863aa23b06456f395404d6
affected
76894f3e2f71177747b8b4763fb180e800279585 - < d017880782cf71f8820ee4a2002843893176501d
affected
76894f3e2f71177747b8b4763fb180e800279585 - < 33f736187d08f6bc822117629f263b97d3df4165
affected
2d046892a493d9760c35fdaefc3017f27f91b621

+1 more versions

Linux

Linux

affected
6.1
unaffected
0 - < 6.1
unaffected
6.1.39 - <= 6.1.*
unaffected
6.3.13 - <= 6.3.*
unaffected
6.4.4 - <= 6.4.*

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now