CVE-2023-1195: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A use-after-free flaw was found in reconn_set_ipaddr_from_hostname in fs/cifs/connect.c in the Linux kernel. The issue occurs when it forgets to set the free pointer server->hostname to NULL, leading to an invalid pointer request.
Affected products
- Linux Linux Kernel: before 6.1 (fixed in 6.1); version 6.1 only
Published 2023-05-18. Last modified 2026-06-17.