{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2023-54280",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-12-30T12:06:44.525Z",
        "datePublished": "2025-12-30T12:23:22.335Z",
        "dateUpdated": "2026-08-05T09:18:52.296Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T09:18:52.296Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix potential race when tree connecting ipc\n\nProtect access of TCP_Server_Info::hostname when building the ipc tree\nname as it might get freed in cifsd thread and thus causing an\nuse-after-free bug in __tree_connect_dfs_target().  Also, while at it,\nupdate status of IPC tcon on success and then avoid any extra tree\nconnects."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:N - The race is in the CIFS/SMB client's DFS reconnect path and is driven entirely by remote peer behaviour — a malicious or compromised SMB/DFS server (or an on-path attacker resetting the TCP session) controls when reconnects occur and which failover targets are returned, and the leaked heap bytes are sent back to that server in the TREE_CONNECT request. Both racing threads (cifsd demux thread and the cifsiod reconnect worker) run automatically over the network connection with no local component.\nAC:L - The attacker controls both sides of the race: dropping the TCP connection forces cifsd into reconnect_dfs_server()/__reconnect_target_unlocked() which kfree()s server->hostname, while the referral target list it supplies guarantees the free happens, and the cifsiod reconnect worker concurrently reads the pointer unlocked. reconnect_dfs_server() retries in a msleep(3000) loop so the window can be hit repeatedly until it lands.\nPR:N - The attacker acts as the SMB/DFS server or as a network attacker on the connection and never authenticates to or holds any account on the victim host. The vulnerable reconnect path runs in kernel threads (cifsd and the cifsiod reconnect worker), so no privileged or unprivileged local process is needed at all.\nUI:N - Against an already-mounted DFS share — the normal persistent state for enterprise fstab/autofs mounts — the entire trigger sequence is kernel-internal: cifsd drops and re-establishes the connection and queues smb2_reconnect_server(), which reaches __tree_connect_dfs_target() with no user process and no victim action.\nS:U - The use-after-free is confined to kernel heap memory of the affected host and does not cross a virtualization, IOMMU, or sandbox boundary. Impact and vulnerable component share the same security authority.\nC:H - The freed hostname buffer is formatted with \"%s\", and string_nocheck() runs with precision -1 (`while (lim--)`), so it reads freed and reallocated heap memory unbounded until a NUL byte, copying up to ~500 bytes into the tree name, which is then transmitted to the remote attacker-controlled server in the SMB2 TREE_CONNECT request — a direct kernel heap disclosure primitive.\nI:H - This is a use-after-free on an attacker-influenced heap object; an attacker who grooms the reallocated kmalloc chunk controls the string used to build the IPC$ tree-connect request, steering the client's connection state, and UAF conditions on the CIFS server/session objects are generally leverageable for stronger corruption primitives.\nA:H - The unbounded scan for a NUL over the freed allocation readily walks off the slab object into unmapped memory, producing a kernel oops/panic (and an immediate KASAN BUG on hardened kernels). The remote attacker can retrigger the reconnect race repeatedly until the client crashes."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/cifs/dfs.c"
                    ],
                    "versions": [
                        {
                            "version": "c88f7dcd6d6429197fc2fd87b54a894ffcd48e8e",
                            "lessThan": "536ec71ba060a02fabe8e22cecb82fe7b3a8708b",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "c88f7dcd6d6429197fc2fd87b54a894ffcd48e8e",
                            "lessThan": "553476df55a111e6a66ad9155256aec0ec1b7ad0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "c88f7dcd6d6429197fc2fd87b54a894ffcd48e8e",
                            "lessThan": "ee20d7c6100752eaf2409d783f4f1449c29ea33d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "81d583baa5f1abd73c755ce1992929debd20b687",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "5.15.81",
                            "lessThan": "5.16",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/cifs/dfs.c"
                    ],
                    "versions": [
                        {
                            "version": "5.16",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.16",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.2.15",
                            "lessThanOrEqual": "6.2.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.3.2",
                            "lessThanOrEqual": "6.3.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.4",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.16",
                                    "versionEndExcluding": "6.2.15"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.16",
                                    "versionEndExcluding": "6.3.2"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.16",
                                    "versionEndExcluding": "6.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.15.81"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/536ec71ba060a02fabe8e22cecb82fe7b3a8708b"
                },
                {
                    "url": "https://git.kernel.org/stable/c/553476df55a111e6a66ad9155256aec0ec1b7ad0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/ee20d7c6100752eaf2409d783f4f1449c29ea33d"
                }
            ],
            "title": "cifs: fix potential race when tree connecting ipc",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}