CVE-2023-52752Use After Free in Linux

CWE-416Use After Free34 documents9 sources
Severity
7.8HIGHNVD
OSV5.5
EPSS
0.0%
top 96.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 21
Latest updateOct 25

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free bug in cifs_debug_data_proc_show() Skip SMB sessions that are being teared down (e.g. @ses->ses_status == SES_EXITING) in cifs_debug_data_proc_show() to avoid use-after-free in @ses. This fixes the following GPF when reading from /proc/fs/cifs/DebugData while mounting and umounting [ 816.251274] general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6d81: 0000 [#1] PREEMPT

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages7 packages

NVDlinux/linux_kernel5.115.15.181+4
Debianlinux/linux_kernel< 5.10.237-1+3
Ubuntulinux/linux_kernel< 5.4.0-192.212+2
CVEListV5linux/linux7f48558e6489d032b1584b0cc9ac4bb11072c0342abdf136784b7edaec7ffe0f4b461b63f9c4c4de+7
debiandebian/linux< linux 6.1.64-1 (bookworm)

Also affects: Debian Linux 11.0

Patches

🔴Vulnerability Details

15
OSV
linux-xilinx-zynqmp vulnerabilities2024-09-18
OSV
linux-raspi-5.4 vulnerabilities2024-08-22
OSV
linux-bluefield vulnerabilities2024-08-21
OSV
linux-azure-5.4 vulnerabilities2024-08-19
OSV
linux-azure vulnerabilities2024-08-14

📋Vendor Advisories

16
Ubuntu
Linux kernel vulnerabilities2024-09-18
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2024-08-22
Ubuntu
Linux kernel (BlueField) vulnerabilities2024-08-21
Ubuntu
Linux kernel (Azure) vulnerabilities2024-08-19
Ubuntu
Linux kernel (Azure) vulnerabilities2024-08-14

📄Research Papers

1
arXiv
PortGPT: Towards Automated Backporting Using Large Language Models2025-10-25

💬Community

1
Bugzilla
CVE-2023-52752 kernel: smb: client: fix use-after-free bug in cifs_debug_data_proc_show()2024-05-22