CVE-2023-52572

cifs: Fix UAF in cifs_demultiplex_thread()

References

Notes

 carnil> Introduced in ec637e3ffb6b ("[CIFS] Avoid extra large buffer allocation (and
 carnil> memcpy) in cifs_readpages"). Vulnerable versions: 2.6.16-rc2.
 bwh> Duplicate of CVE-2023-1192.

Bugs

Status

Branch Status
4.19-buster-security needed
4.19-upstream-stable needed
5.10-bullseye-security needed
5.10-upstream-stable needed
6.1-bookworm-security released (6.1.64-1)
6.1-upstream-stable released (6.1.56) [908b3b5e97d25e879de3d1f172a255665491c2c3]
6.6-upstream-stable N/A "Fixed before branching point"
6.8-upstream-stable N/A "Fixed before branching point"
sid released (6.5.6-1)
upstream released (6.6-rc3) [d527f51331cace562393a8038d870b3e9916686f]