cbcvebase.
CVE-2023-53358
published 2025-09-17

CVE-2023-53358: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue under cocurrent smb2 tree disconnect There is UAF issue under…

PriorityP429high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.16%
6.1th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue under cocurrent smb2 tree disconnect There is UAF issue under cocurrent smb2 tree disconnect. This patch introduce TREE_CONN_EXPIRE flags for tcon to avoid cocurrent access.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < b36295c17fb97424406f0c3ab321b1ccaabb9be8b36295c17fb97424406f0c3ab321b1ccaabb9be8
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < bd80d35725a0cf4df9307bfe2f1a3b2cb983d8e6bd80d35725a0cf4df9307bfe2f1a3b2cb983d8e6
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < dc1c17716c099c90948ebb83e2170dd75a3be6b6dc1c17716c099c90948ebb83e2170dd75a3be6b6
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 39366b47a59d46af15ac57beb0996268bf911f6a39366b47a59d46af15ac57beb0996268bf911f6a
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 30210947a343b6b3ca13adc9bfc88e1543e16dd530210947a343b6b3ca13adc9bfc88e1543e16dd5
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 5.15 < 5.15.1455.15.145
linuxlinux_kernel>= 5.16 < 6.1.286.1.28
linuxlinux_kernel>= 6.2 < 6.2.156.2.15
linuxlinux_kernel>= 6.3 < 6.3.26.3.2

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.