PT-2025-37687 · Linux+3 · Linux Kernel+3

Published

2025-09-15

·

Updated

2026-04-14

·

CVE-2023-53246

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to CIFS (Common Internet File System) and DFS (Distributed File System) traversal. When compiled without the CONFIG CIFS DFS UPCALL option enabled, a NULL pointer dereference can occur in the VFS follow automount() function during DFS referral link traversal. This is due to retained logic for mapping CIFS attributes to dentry flags, even when the upcall mechanism is disabled. The issue results in a kernel NULL pointer dereference, potentially leading to system instability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2026-05880
CVE-2023-53246
RHSA-2024:2394
SUSE-SU-2025:03614-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse