In the Linux kernel, the following vulnerability has been resolved:
cifs: fix potential memory leaks in session setup
Make sure to free cifsses::authkey.response before allocating it as we might end up leaking memory in reconnect or mounting.
[
{
"id": "CVE-2023-53008-0678da3e",
"signature_type": "Line",
"digest": {
"line_hashes": [
"176413479164976145726970936142190811138",
"292438494161285721725054730323287108681",
"127119049886917894935808186118676872389",
"233098271109362874671065327347609351271"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2fe58d977ee05da5bb89ef5dc4f5bf2dc15db46f",
"target": {
"file": "fs/cifs/smb2pdu.c"
}
},
{
"id": "CVE-2023-53008-535ef77c",
"signature_type": "Line",
"digest": {
"line_hashes": [
"11819294804773023539130453148308800447",
"316027580957404927875061016471040753588",
"52022934863883484282722805559726291039"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2fe58d977ee05da5bb89ef5dc4f5bf2dc15db46f",
"target": {
"file": "fs/cifs/cifsencrypt.c"
}
},
{
"id": "CVE-2023-53008-5f051e41",
"signature_type": "Line",
"digest": {
"line_hashes": [
"124694747691300695863352784395935416920",
"288079369686436738103373016724446948899",
"234397821156402895384364934437260537624",
"88112815743872382698225527055379721747",
"97106481230578813549459518994502175009",
"52170099430521840089414955524536422437",
"272051747008186209737342566102775207496"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@893d45394dbe4b5cbf3723c19e2ccc8b93a6ac9b",
"target": {
"file": "fs/cifs/sess.c"
}
},
{
"id": "CVE-2023-53008-7e730db5",
"signature_type": "Line",
"digest": {
"line_hashes": [
"124694747691300695863352784395935416920",
"288079369686436738103373016724446948899",
"234397821156402895384364934437260537624",
"88112815743872382698225527055379721747",
"97106481230578813549459518994502175009",
"52170099430521840089414955524536422437",
"272051747008186209737342566102775207496"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2fe58d977ee05da5bb89ef5dc4f5bf2dc15db46f",
"target": {
"file": "fs/cifs/sess.c"
}
},
{
"id": "CVE-2023-53008-8871f43a",
"signature_type": "Function",
"digest": {
"length": 1765.0,
"function_hash": "44315696282432286842675740999658605967"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2fe58d977ee05da5bb89ef5dc4f5bf2dc15db46f",
"target": {
"function": "SMB2_auth_kerberos",
"file": "fs/cifs/smb2pdu.c"
}
},
{
"id": "CVE-2023-53008-920a934e",
"signature_type": "Function",
"digest": {
"length": 2290.0,
"function_hash": "275197493018482291205732308551600803610"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2fe58d977ee05da5bb89ef5dc4f5bf2dc15db46f",
"target": {
"function": "decode_ntlmssp_challenge",
"file": "fs/cifs/sess.c"
}
},
{
"id": "CVE-2023-53008-9a6568a1",
"signature_type": "Function",
"digest": {
"length": 3023.0,
"function_hash": "176571250462509873034876588842094230216"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@893d45394dbe4b5cbf3723c19e2ccc8b93a6ac9b",
"target": {
"function": "sess_auth_kerberos",
"file": "fs/cifs/sess.c"
}
},
{
"id": "CVE-2023-53008-a5e8abf4",
"signature_type": "Function",
"digest": {
"length": 3023.0,
"function_hash": "176571250462509873034876588842094230216"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2fe58d977ee05da5bb89ef5dc4f5bf2dc15db46f",
"target": {
"function": "sess_auth_kerberos",
"file": "fs/cifs/sess.c"
}
},
{
"id": "CVE-2023-53008-ca1830f9",
"signature_type": "Function",
"digest": {
"length": 870.0,
"function_hash": "213367052148434399673982002260121388392"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2fe58d977ee05da5bb89ef5dc4f5bf2dc15db46f",
"target": {
"function": "build_avpair_blob",
"file": "fs/cifs/cifsencrypt.c"
}
},
{
"id": "CVE-2023-53008-e048ad10",
"signature_type": "Function",
"digest": {
"length": 1765.0,
"function_hash": "44315696282432286842675740999658605967"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@893d45394dbe4b5cbf3723c19e2ccc8b93a6ac9b",
"target": {
"function": "SMB2_auth_kerberos",
"file": "fs/cifs/smb2pdu.c"
}
},
{
"id": "CVE-2023-53008-e1845019",
"signature_type": "Line",
"digest": {
"line_hashes": [
"176413479164976145726970936142190811138",
"292438494161285721725054730323287108681",
"127119049886917894935808186118676872389",
"233098271109362874671065327347609351271"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@893d45394dbe4b5cbf3723c19e2ccc8b93a6ac9b",
"target": {
"file": "fs/cifs/smb2pdu.c"
}
},
{
"id": "CVE-2023-53008-f4fede34",
"signature_type": "Function",
"digest": {
"length": 870.0,
"function_hash": "213367052148434399673982002260121388392"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@893d45394dbe4b5cbf3723c19e2ccc8b93a6ac9b",
"target": {
"function": "build_avpair_blob",
"file": "fs/cifs/cifsencrypt.c"
}
},
{
"id": "CVE-2023-53008-f77d56bf",
"signature_type": "Function",
"digest": {
"length": 2290.0,
"function_hash": "275197493018482291205732308551600803610"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@893d45394dbe4b5cbf3723c19e2ccc8b93a6ac9b",
"target": {
"function": "decode_ntlmssp_challenge",
"file": "fs/cifs/sess.c"
}
},
{
"id": "CVE-2023-53008-fa25f1d9",
"signature_type": "Line",
"digest": {
"line_hashes": [
"11819294804773023539130453148308800447",
"316027580957404927875061016471040753588",
"52022934863883484282722805559726291039"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@893d45394dbe4b5cbf3723c19e2ccc8b93a6ac9b",
"target": {
"file": "fs/cifs/cifsencrypt.c"
}
}
]