Executive brief
The Linux kernel's CIFS (Common Internet File System) client, used for accessing network file shares on Windows and Samba servers, contained a use-after-free vulnerability in how it manages server connection hostname data. An attacker could exploit this flaw during network reconnection scenarios to crash the system or potentially execute arbitrary code, affecting file server availability and data access for organizations relying on CIFS-based file sharing.
Technical details
The vulnerability is a use-after-free bug in the CIFS TCP_Server_Info structure's hostname field. The TCP_Server_Info::hostname pointer may be updated multiple times during reconnect operations, but concurrent access to this field from debug/stats code paths was not properly synchronized with a lock. The fix adds spin_lock protection (srv_lock) around all accesses to server->hostname outside the reconnect path in fs/cifs/cifs_debug.c, fs/cifs/cifs_debug.h, and fs/cifs/connect.c. Attack vector is local/adjacent network as it requires triggering reconnection conditions. The vulnerability was patched by adding proper locking to prevent race conditions on hostname updates and reads.
Affected products
- Linux Linux kernel multiple kernel versions (patches distributed across linux-2.6.11.y through linux-7.2.y and rolling branches)
Timeline
- 2023-04-21: disclosed: Patch authored by Paulo Alcantara
- 2023-05-11: patched: Patches committed to stable kernel branches
- 2025-12-08: advisory: CVE-2023-53751 published