Home

Description

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix lost destroy smbd connection when MR allocate failed If the MR allocate failed, the smb direct connection info is NULL, then smbd_destroy() will directly return, then the connection info will be leaked. Let's set the smb direct connection info to the server before call smbd_destroy().

PUBLISHED Reserved 2025-12-30 | Published 2025-12-30 | Updated 2025-12-30 | Assigner Linux

Product status

Default status
unaffected

c7398583340a6d82b8bb7f7f21edcde27dc6a898 (git) before d303e25887127364a6765eaf7ac68aa2bac518a9
affected

c7398583340a6d82b8bb7f7f21edcde27dc6a898 (git) before 324c0c34fff1affd436e509325cb46739209704e
affected

c7398583340a6d82b8bb7f7f21edcde27dc6a898 (git) before caac205e0d5b44c4c23a10c6c0976d50ebe16ac2
affected

c7398583340a6d82b8bb7f7f21edcde27dc6a898 (git) before 46cd6c639cddba2bd2d810ceb16bb20374ad75b0
affected

c7398583340a6d82b8bb7f7f21edcde27dc6a898 (git) before c51ae01104b318bf15f3c5097faba5c72addba7a
affected

c7398583340a6d82b8bb7f7f21edcde27dc6a898 (git) before 04b7e13b8a13264282f874db5378fc3d3253cfac
affected

c7398583340a6d82b8bb7f7f21edcde27dc6a898 (git) before e9d3401d95d62a9531082cd2453ed42f2740e3fd
affected

Default status
affected

4.16
affected

Any version before 4.16
unaffected

4.19.276 (semver)
unaffected

5.4.235 (semver)
unaffected

5.10.173 (semver)
unaffected

5.15.99 (semver)
unaffected

6.1.16 (semver)
unaffected

6.2.3 (semver)
unaffected

6.3 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/d303e25887127364a6765eaf7ac68aa2bac518a9

git.kernel.org/...c/324c0c34fff1affd436e509325cb46739209704e

git.kernel.org/...c/caac205e0d5b44c4c23a10c6c0976d50ebe16ac2

git.kernel.org/...c/46cd6c639cddba2bd2d810ceb16bb20374ad75b0

git.kernel.org/...c/c51ae01104b318bf15f3c5097faba5c72addba7a

git.kernel.org/...c/04b7e13b8a13264282f874db5378fc3d3253cfac

git.kernel.org/...c/e9d3401d95d62a9531082cd2453ed42f2740e3fd

cve.org (CVE-2023-54260)

nvd.nist.gov (CVE-2023-54260)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.