Linux Kernel Vulnerability in SMB2 Handling Affecting CIFS Client
CVE-2023-53377

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
18 September 2025

What is CVE-2023-53377?

A vulnerability in the Linux Kernel related to the SMB2 compound operations presents a risk of use-after-free, which can lead to unpredictable behavior and difficult debugging challenges. The issue arises from improper management of memory during processing of CIFS client requests. The vulnerability was discovered during stress tests with KASAN (Kernel Address Sanitizer) enabled, prompting a fix that reorders the memory freeing process to occur after its final usage. This ensures the integrity of resources and mitigates potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 76894f3e2f71177747b8b4763fb180e800279585 < 4fe07d55a5461e66a55fbefb57f85ff0facea32b

Linux 76894f3e2f71177747b8b4763fb180e800279585

Linux 76894f3e2f71177747b8b4763fb180e800279585

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.