CVE-2023-53358
published 2025-09-17CVE-2023-53358: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue under cocurrent smb2 tree disconnect There is UAF issue under…
PriorityP429high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.16%
6.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix racy issue under cocurrent smb2 tree disconnect
There is UAF issue under cocurrent smb2 tree disconnect.
This patch introduce TREE_CONN_EXPIRE flags for tcon to avoid cocurrent
access.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 0626e6641f6b467447c81dd7678a69c66f7746cf < b36295c17fb97424406f0c3ab321b1ccaabb9be8 | b36295c17fb97424406f0c3ab321b1ccaabb9be8 |
| linux | linux | >= 0626e6641f6b467447c81dd7678a69c66f7746cf < bd80d35725a0cf4df9307bfe2f1a3b2cb983d8e6 | bd80d35725a0cf4df9307bfe2f1a3b2cb983d8e6 |
| linux | linux | >= 0626e6641f6b467447c81dd7678a69c66f7746cf < dc1c17716c099c90948ebb83e2170dd75a3be6b6 | dc1c17716c099c90948ebb83e2170dd75a3be6b6 |
| linux | linux | >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 39366b47a59d46af15ac57beb0996268bf911f6a | 39366b47a59d46af15ac57beb0996268bf911f6a |
| linux | linux | >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 30210947a343b6b3ca13adc9bfc88e1543e16dd5 | 30210947a343b6b3ca13adc9bfc88e1543e16dd5 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 5.15 < 5.15.145 | 5.15.145 |
| linux | linux_kernel | >= 5.16 < 6.1.28 | 6.1.28 |
| linux | linux_kernel | >= 6.2 < 6.2.15 | 6.2.15 |
| linux | linux_kernel | >= 6.3 < 6.3.2 | 6.3.2 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-53358: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue under cocurrent smb2 tree disconnect There is UAF issue unde
osv·2025-09-17·CVSS 7.0
CVE-2023-53358 [HIGH] CVE-2023-53358: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue under cocurrent smb2 tree disconnect There is UAF issue unde
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue under cocurrent smb2 tree disconnect There is UAF issue under cocurrent smb2 tree disconnect. This patch introduce TREE_CONN_EXPIRE flags for tcon to avoid cocurrent access.
GHSA
GHSA-j8wr-29h3-4xqr: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix racy issue under cocurrent smb2 tree disconnect
There is UAF issue un
ghsa_unreviewed·2025-09-17
CVE-2023-53358 [HIGH] CWE-416 GHSA-j8wr-29h3-4xqr: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix racy issue under cocurrent smb2 tree disconnect
There is UAF issue un
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix racy issue under cocurrent smb2 tree disconnect
There is UAF issue under cocurrent smb2 tree disconnect.
This patch introduce TREE_CONN_EXPIRE flags for tcon to avoid cocurrent
access.
Red Hat
kernel: ksmbd: fix racy issue under cocurrent smb2 tree disconnect
vendor_redhat·2025-09-17·CVSS 7.0
CVE-2023-53358 [HIGH] kernel: ksmbd: fix racy issue under cocurrent smb2 tree disconnect
kernel: ksmbd: fix racy issue under cocurrent smb2 tree disconnect
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix racy issue under cocurrent smb2 tree disconnect
There is UAF issue under cocurrent smb2 tree disconnect.
This patch introduce TREE_CONN_EXPIRE flags for tcon to avoid cocurrent
access.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enter
Debian
CVE-2023-53358: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
vendor_debian·2023·CVSS 7.0
CVE-2023-53358 [HIGH] CVE-2023-53358: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue under cocurrent smb2 tree disconnect There is UAF issue under cocurrent smb2 tree disconnect. This patch introduce TREE_CONN_EXPIRE flags for tcon to avoid cocurrent access.
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/30210947a343b6b3ca13adc9bfc88e1543e16dd5https://git.kernel.org/stable/c/39366b47a59d46af15ac57beb0996268bf911f6ahttps://git.kernel.org/stable/c/b36295c17fb97424406f0c3ab321b1ccaabb9be8https://git.kernel.org/stable/c/bd80d35725a0cf4df9307bfe2f1a3b2cb983d8e6https://git.kernel.org/stable/c/dc1c17716c099c90948ebb83e2170dd75a3be6b6
2025-09-17
Published