Use After Free Vulnerability in Linux Kernel's SMB2 Tree Disconnect Feature
CVE-2023-53358

7HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2023-53358?

The Linux kernel has addressed a use-after-free vulnerability found in the concurrent handling of the SMB2 tree disconnect operation within the ksmbd component. This issue could be exploited to cause unexpected behavior or crashes by manipulating concurrent access to resources. To mitigate this risk, a patch has been implemented that introduces the TREE_CONN_EXPIRE flag, effectively managing concurrent access and enhancing overall system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 0626e6641f6b467447c81dd7678a69c66f7746cf

Linux 0626e6641f6b467447c81dd7678a69c66f7746cf

Linux 0626e6641f6b467447c81dd7678a69c66f7746cf

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.