{"id":"CVE-2023-53377","summary":"cifs: prevent use-after-free by freeing the cfile later","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: prevent use-after-free by freeing the cfile later\n\nIn smb2_compound_op we have a possible use-after-free\nwhich can cause hard to debug problems later on.\n\nThis was revealed during stress testing with KASAN enabled\nkernel. Fixing it by moving the cfile free call to\na few lines below, after the usage.","modified":"2026-04-02T09:44:07.226649Z","published":"2025-09-18T13:33:23.162Z","related":["SUSE-SU-2025:03600-1","SUSE-SU-2025:03615-1","SUSE-SU-2025:03628-1","SUSE-SU-2025:03634-1","SUSE-SU-2025:20851-1","SUSE-SU-2025:20861-1","SUSE-SU-2025:20870-1","SUSE-SU-2025:20898-1","SUSE-SU-2025:3716-1","SUSE-SU-2025:3751-1","SUSE-SU-2025:3761-1","SUSE-SU-2025:4057-1","SUSE-SU-2025:4132-1","SUSE-SU-2025:4141-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53377.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/33f736187d08f6bc822117629f263b97d3df4165"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4fe07d55a5461e66a55fbefb57f85ff0facea32b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b6353518ef8180816e863aa23b06456f395404d6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d017880782cf71f8820ee4a2002843893176501d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53377.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-53377"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"76894f3e2f71177747b8b4763fb180e800279585"},{"fixed":"4fe07d55a5461e66a55fbefb57f85ff0facea32b"},{"fixed":"b6353518ef8180816e863aa23b06456f395404d6"},{"fixed":"d017880782cf71f8820ee4a2002843893176501d"},{"fixed":"33f736187d08f6bc822117629f263b97d3df4165"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"0"},{"last_affected":"2d046892a493d9760c35fdaefc3017f27f91b621"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53377.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}