Use-after-free in Linux kernel - CVE-2023-53047

 

Use-after-free in Linux kernel - CVE-2023-53047

Published: May 4, 2025 / Updated: May 10, 2025


Vulnerability identifier: #VU108437
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-53047
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the tconInfoAlloc() and tconInfoFree() functions in fs/cifs/misc.c, within the DECLARE_RWSEM(), dfs_cache_destroy(), dfs_cache_add_refsrv_session() and dfs_cache_remount_fs() functions in fs/cifs/dfs_cache.c, within the get_session(), get_dfs_conn(), __dfs_mount_share() and dfs_mount_share() functions in fs/cifs/dfs.c, within the cifs_mount() and cifs_umount() functions in fs/cifs/connect.c. A local user can escalate privileges on the system.


Affected software

Linux kernel
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel (Red Hat package)
kernel-rt (Red Hat package)

How to mitigate CVE-2023-53047

Install update from vendor's website.

Linux kernel - addressed in versions 5.10.177, 5.15.105, 6.1.22, 6.2.9, 6.3
kernel (Red Hat package) - addressed in versions 5.14.0-70.144.1.el9_0, 5.14.0-284.131.1.el9_2
kernel-rt (Red Hat package) - addressed in versions 5.14.0-70.144.1.rt21.216.el9_0, 5.14.0-284.131.1.rt14.416.el9_2

External References

Related Security Bulletins