CVE-2023-53052
Linux Kernel vulnerability analysis and mitigation

Overview

A use-after-free vulnerability (CVE-2023-53052) was discovered in the Linux kernel's CIFS implementation, specifically in the refreshcacheworker() function. The vulnerability was disclosed on May 2, 2025, affecting the Linux kernel's CIFS (Common Internet File System) subsystem. The issue occurs because DFS root sessions were being put in cifs_umount() while the DFS cache refresher was being executed (NVD, Wiz).

Technical details

The vulnerability manifests as a use-after-free bug in the refreshtcon.isra.0 function within the CIFS module. The issue was detected by KASAN (Kernel Address Sanitizer) which reported a read of size 8 at a specific memory address by the kworker task. According to Red Hat's assessment, the vulnerability has a CVSS v3.1 score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) (Red Hat).

Impact

The use-after-free vulnerability could potentially lead to system crashes or memory corruption in systems using the CIFS filesystem module. This could affect systems that utilize DFS (Distributed File System) functionality within the Linux kernel (Wiz).

Mitigation and workarounds

The issue has been fixed by modifying DFS root sessions to have the same lifetime as DFS tcons, preventing the use-after-free bug in the DFS cache refresher and other places that require IPCs to get new DFS referrals. The fix also removes mount group handling in DFS cache as it is no longer needed. Fixed versions are available in various Linux distributions, including Debian Trixie (6.12.25-1) and Sid (6.12.27-1) (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management