Use-after-free in smb2_is_status_io_timeout()
Published Nov 1, 2023
6.5
MEDIUMCVSS 3.1
EPSS 1.10%
Description
A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a denial of service.
Affected products
-
-
-
- Vendor n/a Product Kernel Defaultaffected
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Fedora | Fedora | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
| |||
| n/a | Kernel | affected |
|
Configuration 1
- < 6.4
Configuration 2
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.9.1.el8_9
Fixed · RHSA-2023:7549
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.9.1.rt7.311.el8_9
Fixed · RHSA-2023:7548
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.133.1.el8_2
Fixed · RHSA-2024:2006
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-0:4.18.0-193.133.1.el8_2
Fixed · RHSA-2024:2006
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-rt-0:4.18.0-193.133.1.rt13.184.el8_2
Fixed · RHSA-2024:2008
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
kernel-0:4.18.0-193.133.1.el8_2
Fixed · RHSA-2024:2006
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.120.1.el8_4
Fixed · RHSA-2024:0562
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-0:4.18.0-305.120.1.el8_4
Fixed · RHSA-2024:0562
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-rt-0:4.18.0-305.120.1.rt7.196.el8_4
Fixed · RHSA-2024:0563
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
kernel-0:4.18.0-305.120.1.el8_4
Fixed · RHSA-2024:0562
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.36.1.el8_8
Fixed · RHSA-2023:7539
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.13.1.el9_3
Fixed · RHSA-2023:7749
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.13.1.el9_3
Fixed · RHSA-2023:7749
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.93.2.el9_0
Fixed · RHSA-2024:1250
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.93.1.rt21.165.el9_0
Fixed · RHSA-2024:1306
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.48.1.el9_2
Fixed · RHSA-2024:0448
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.48.1.rt14.333.el9_2
Fixed · RHSA-2024:0439
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.9.1.el8_9 | Fixed | RHSA-2023:7549 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.9.1.rt7.311.el8_9 | Fixed | RHSA-2023:7548 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.133.1.el8_2 | Fixed | RHSA-2024:2006 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-0:4.18.0-193.133.1.el8_2 | Fixed | RHSA-2024:2006 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-rt-0:4.18.0-193.133.1.rt13.184.el8_2 | Fixed | RHSA-2024:2008 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | kernel-0:4.18.0-193.133.1.el8_2 | Fixed | RHSA-2024:2006 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.120.1.el8_4 | Fixed | RHSA-2024:0562 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-0:4.18.0-305.120.1.el8_4 | Fixed | RHSA-2024:0562 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-rt-0:4.18.0-305.120.1.rt7.196.el8_4 | Fixed | RHSA-2024:0563 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | kernel-0:4.18.0-305.120.1.el8_4 | Fixed | RHSA-2024:0562 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.36.1.el8_8 | Fixed | RHSA-2023:7539 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.13.1.el9_3 | Fixed | RHSA-2023:7749 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.13.1.el9_3 | Fixed | RHSA-2023:7749 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.93.2.el9_0 | Fixed | RHSA-2024:1250 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.93.1.rt21.165.el9_0 | Fixed | RHSA-2024:1306 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.48.1.el9_2 | Fixed | RHSA-2024:0448 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.48.1.rt14.333.el9_2 | Fixed | RHSA-2024:0439 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
Because analysis indicates that this issue will only cause momentary interruptions to connections, Red Hat rates the impact of this flaw as Low.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 26, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.10% (0.01104) | 64.52th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.10% (0.01104) | 61.34th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.02% (0.00023) | 3.60th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00052) | 22.09th | v3 (v2023.03.01) |
| Jun 1, 2024 | 0.05% (0.00050) | 18.75th | v3 (v2023.03.01) |
| Nov 10, 2023 | 0.05% (0.00050) | 16.74th | v3 (v2023.03.01) |
| Nov 2, 2023 | 0.05% (0.00053) | 19.48th | v3 (v2023.03.01) |
References (6)
- https://access.redhat.com/security/cve/CVE-2023-1192 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2154178 issue-trackingx_refsource_REDHATIssue Tracking
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d527f51331cace562393a8038d870b3e9916686f
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d527f51331cace562393a8038d870b3e9916686fCVE-2023-52
- https://nvd.nist.gov/vuln/detail/CVE-2023-1192
- https://www.cve.org/CVERecord?id=CVE-2023-1192
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-1192 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2154178 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d527f51331cace562393a8038d870b3e9916686f | ||
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d527f51331cace562393a8038d870b3e9916686fCVE-2023-52 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2023-1192 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-1192 |
Change history (0)
No recorded changes yet.