CVE-2022-27239
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
Affected (60)
Products: Samba: Cifs Utils · Debian: Debian Linux · Suse: Caas Platform, Enterprise Storage, Linux Enterprise Desktop, Linux Enterprise High Performance Computing, Linux Enterprise Micro, Linux Enterprise Point Of Service, Linux Enterprise Real Time, Linux Enterprise Server, Linux Enterprise Software Development Kit, Linux Enterprise Storage, Manager Proxy, Manager Retail Branch Server, Manager Server, Openstack Cloud, Openstack Cloud Crowbar · +2 more
Show all products
Samba: Cifs Utils · Debian: Debian Linux · Suse: Caas Platform, Enterprise Storage, Linux Enterprise Desktop, Linux Enterprise High Performance Computing, Linux Enterprise Micro, Linux Enterprise Point Of Service, Linux Enterprise Real Time, Linux Enterprise Server, Linux Enterprise Software Development Kit, Linux Enterprise Storage, Manager Proxy, Manager Retail Branch Server, Manager Server, Openstack Cloud, Openstack Cloud Crowbar · Hp: Helion Openstack · Fedoraproject: Fedora
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.15 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 | |
| Version 6.0 | |
| Version 15 sp3 | |
| Version 12.0 sp5 | |
| Version 5.2 | |
| Version 11.0 sp3 | |
| Version 15.0 sp2 | |
| Version 11 sp3 | |
| Version 12 sp5 | |
| Version 7.1 | |
| Version 4.1 | |
| Version 4.1 | |
| Version 4.1 | |
| Version 8.0 | |
| Version 8.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 34 |
References (22)
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue TrackingPermissions RequiredVendor Advisory
Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPermissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.