CVE-2023-54260 — Missing Release of Resource after Effective Lifetime in Linux
Severity
3.3LOW
No vectorEPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 30
Description
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix lost destroy smbd connection when MR allocate failed
If the MR allocate failed, the smb direct connection info is NULL,
then smbd_destroy() will directly return, then the connection info
will be leaked.
Let's set the smb direct connection info to the server before call
smbd_destroy().
Affected Packages4 packages
▶CVEListV5linux/linuxc7398583340a6d82b8bb7f7f21edcde27dc6a898 — d303e25887127364a6765eaf7ac68aa2bac518a9+7
🔴Vulnerability Details
3OSV▶
CVE-2023-54260: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix lost destroy smbd connection when MR allocate failed If the MR allocate↗2025-12-30
GHSA▶
GHSA-53m3-7xgw-52vj: In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix lost destroy smbd connection when MR allocate failed
If the MR allocat↗2025-12-30