PT-2023-5679 · Linux+7 · Linux Kernel+7

Published

2023-09-28

·

Updated

2026-03-31

·

CVE-2023-5345

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3 fs context parse param, ctx->password was freed but the field was not set to NULL which could lead to double free.
Recommendations Upgrade past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705 to resolve the issue. As a temporary workaround, consider disabling the smb3 fs context parse param function until a patch is available. Restrict access to the vulnerable fs/smb/client component to minimize the risk of exploitation. Avoid using the ctx->password field in the affected component until the issue is resolved.

Exploit

Fix

LPE

Use After Free

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-7004
ALT-PU-2023-7787
ALT-PU-2023-7838
ALT-PU-2023-8395
ALT-PU-2024-6818
AZL-31149
AZL-31730
BDU:2023-06347
CVE-2023-5345
LSN-0100-1
MGASA-2023-0328
MGASA-2023-0331
OPENSUSE-SU-2023_4035-1
OPENSUSE-SU-2023_4057-1
OPENSUSE-SU-2023_4058-1
OPENSUSE-SU-2023_4071-1
OPENSUSE-SU-2023_4072-1
OPENSUSE-SU-2023_4072-2
OPENSUSE-SU-2023_4775-1
OPENSUSE-SU-2023_4848-1
OPENSUSE-SU-2023_4872-1
OPENSUSE-SU-2024:13305-1
OPENSUSE-SU-2024:13704-1
RHSA-2023:7734
RHSA-2023:7749
RHSA-2023_7749
RXSA-2023:7749
SUSE-SU-2023:4035-1
SUSE-SU-2023:4057-1
SUSE-SU-2023:4058-1
SUSE-SU-2023:4071-1
SUSE-SU-2023:4072-1
SUSE-SU-2023:4072-2
SUSE-SU-2023:4093-1
SUSE-SU-2023:4766-1
SUSE-SU-2023:4775-1
SUSE-SU-2023:4801-1
SUSE-SU-2023:4805-1
SUSE-SU-2023:4822-1
SUSE-SU-2023:4841-1
SUSE-SU-2023:4848-1
SUSE-SU-2023:4863-1
SUSE-SU-2023:4872-1
USN-6461-1
USN-6502-1
USN-6502-2
USN-6502-3
USN-6502-4
USN-6503-1
USN-6520-1
USN-6537-1
USN-6572-1
USN-6607-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu