cbcvebase.
CVE-2023-52752
published 2024-05-21

CVE-2023-52752: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free bug in cifs_debug_data_proc_show() Skip SMB sessions that…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.0th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free bug in cifs_debug_data_proc_show() Skip SMB sessions that are being teared down (e.g. @ses->ses_status == SES_EXITING) in cifs_debug_data_proc_show() to avoid use-after-free in @ses. This fixes the following GPF when reading from /proc/fs/cifs/DebugData while mounting and umounting [ 816.251274] general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6d81: 0000 [#1] PREEMPT SMP NOPTI ... [ 816.260138] Call Trace: [ 816.260329] [ 816.260499] ? die_addr+0x36/0x90 [ 816.260762] ? exc_general_protection+0x1b3/0x410 [ 816.261126] ? asm_exc_general_protection+0x26/0x30 [ 816.261502] ? cifs_debug_tcon+0xbd/0x240 [cifs] [ 816.261878] ? cifs_debug_tcon+0xab/0x240 [cifs] [ 816.262249] cifs_debug_data_proc_show+0x516/0xdb0 [cifs] [ 816.262689] ? seq_read_iter+0x379/0x470 [ 816.262995] seq_read_iter+0x118/0x470 [ 816.263291] proc_reg_read_iter+0x53/0x90 [ 816.263596] ? srso_alias_return_thunk+0x5/0x7f [ 816.263945] vfs_read+0x201/0x350 [ 816.264211] ksys_read+0x75/0x100 [ 816.264472] do_syscall_64+0x3f/0x90 [ 816.264750] entry_SYSCALL_64_after_hwframe+0x6e/0xd8 [ 816.265135] RIP: 0033:0x7fd5e669d381

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 3.12.48 < 3.133.13
linuxlinux>= 7f48558e6489d032b1584b0cc9ac4bb11072c034 < 2abdf136784b7edaec7ffe0f4b461b63f9c4c4de2abdf136784b7edaec7ffe0f4b461b63f9c4c4de
linuxlinux>= 7f48558e6489d032b1584b0cc9ac4bb11072c034 < 336a066990bb3962c46daf574ace596bda9303ce336a066990bb3962c46daf574ace596bda9303ce
linuxlinux>= 7f48558e6489d032b1584b0cc9ac4bb11072c034 < 558817597d5fbd7af31f891b67b0fd20f0d047b7558817597d5fbd7af31f891b67b0fd20f0d047b7
linuxlinux>= 7f48558e6489d032b1584b0cc9ac4bb11072c034 < 89929ea46f9cc11ba66d2c64713aa5d5dc723b0989929ea46f9cc11ba66d2c64713aa5d5dc723b09
linuxlinux>= 7f48558e6489d032b1584b0cc9ac4bb11072c034 < 0ab6f842452ce2cae04209d4671ac6289d0aef8a0ab6f842452ce2cae04209d4671ac6289d0aef8a
linuxlinux>= 7f48558e6489d032b1584b0cc9ac4bb11072c034 < d328c09ee9f15ee5a26431f5aad7c9239fa85e62d328c09ee9f15ee5a26431f5aad7c9239fa85e62
linuxlinux_kernel< 5.10.2375.10.237
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-117.1275.15.0-117.127
linuxlinux_kernel>= 0 < 4.4.0-257.2914.4.0-257.291
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.646.1.64
linuxlinux_kernel>= 6.2 < 6.5.136.5.13
linuxlinux_kernel>= 6.6 < 6.6.36.6.3
msrccbl2_kernel_5.15.167.1-2_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.