cve/2023/CVE-2023-1192.md
2024-05-25 21:48:12 +02:00

1.3 KiB

CVE-2023-1192

Description

A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a denial of service.

POC

Reference

No PoCs from references.

Github