CVE-2023-54280: Linux

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential race when tree connecting ipc Protect access of TCP_Server_Info::hostname when building the ipc tree name as it might get freed in cifsd thread and thus causing an use-after-free bug in __tree_connect_dfs_target(). Also, while at it, update status of IPC tcon on success and then avoid any extra tree connects.

Affected products

  • Linux Linux: from 5.15.81, before 5.16 (fixed in 5.16); from 5.16, before 6.2.15 (fixed in 6.2.15); from 6.3, before 6.3.2 (fixed in 6.3.2)

Published 2025-12-30. Last modified 2026-08-04.