CVE-2023-54260Missing Release of Resource after Effective Lifetime in Linux

Severity
3.3LOW
No vector
EPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix lost destroy smbd connection when MR allocate failed If the MR allocate failed, the smb direct connection info is NULL, then smbd_destroy() will directly return, then the connection info will be leaked. Let's set the smb direct connection info to the server before call smbd_destroy().

Affected Packages4 packages

Linuxlinux/linux_kernel4.16.04.19.276+5
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linuxc7398583340a6d82b8bb7f7f21edcde27dc6a898d303e25887127364a6765eaf7ac68aa2bac518a9+7
debiandebian/linux< linux 6.1.20-1 (bookworm)

🔴Vulnerability Details

3
OSV
CVE-2023-54260: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix lost destroy smbd connection when MR allocate failed If the MR allocate2025-12-30
OSV
cifs: Fix lost destroy smbd connection when MR allocate failed2025-12-30
GHSA
GHSA-53m3-7xgw-52vj: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix lost destroy smbd connection when MR allocate failed If the MR allocat2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: cifs: Fix lost destroy smbd connection when MR allocate failed2025-12-30
Debian
CVE-2023-54260: linux - In the Linux kernel, the following vulnerability has been resolved: cifs: Fix l...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54260 Impact, Exploitability, and Mitigation Steps | Wiz