7.8

CVE-2022-27239

In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Samba ≫ Cifs-utils Version < 6.15
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Suse ≫ Caas Platform Version 4.0
Suse ≫ Enterprise Storage Version 6.0
Suse ≫ Enterprise Storage Version 7.0
Suse ≫ Linux Enterprise Point Of Service Version 11.0 Update sp3
Suse ≫ Linux Enterprise Storage Version 7.1
Suse ≫ Manager Proxy Version 4.1
Suse ≫ Manager Proxy Version 4.2
Suse ≫ Manager Proxy Version 4.3
Suse ≫ Manager Server Version 4.1
Suse ≫ Manager Server Version 4.2
Suse ≫ Manager Server Version 4.3
Suse ≫ Openstack Cloud Version 8.0
Suse ≫ Openstack Cloud Version 9.0
Suse ≫ Openstack Cloud Crowbar Version 8.0
Suse ≫ Openstack Cloud Crowbar Version 9.0
Suse ≫ Linux Enterprise Desktop Version 15 Update sp3
Suse ≫ Linux Enterprise Desktop Version 15 Update sp4
Suse ≫ Linux Enterprise High Performance Computing Version 12.0 Update sp5 SwEdition -
Suse ≫ Linux Enterprise High Performance Computing Version 15.0 Update - SwEdition ltss
Suse ≫ Linux Enterprise High Performance Computing Version 15.0 Update sp1 SwEdition espos
Suse ≫ Linux Enterprise High Performance Computing Version 15.0 Update sp1 SwEdition ltss
Suse ≫ Linux Enterprise High Performance Computing Version 15.0 Update sp2 SwEdition espos
Suse ≫ Linux Enterprise High Performance Computing Version 15.0 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise High Performance Computing Version 15.0 Update sp3 SwEdition -
Suse ≫ Linux Enterprise High Performance Computing Version 15.0 Update sp4 SwEdition -
Suse ≫ Linux Enterprise Micro Version 5.2 SwPlatform -
Suse ≫ Linux Enterprise Micro Version 5.2 SwPlatform rancher
Suse ≫ Linux Enterprise Real Time Version 15.0 Update sp2
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform -
Suse ≫ Linux Enterprise Server Version 11 Update sp4 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 12 Update sp2 SwEdition business_critical_linux SwPlatform -
Suse ≫ Linux Enterprise Server Version 12 Update sp3 SwPlatform sap
Suse ≫ Linux Enterprise Server Version 12 Update sp3 SwEdition business_critical_linux SwPlatform -
Suse ≫ Linux Enterprise Server Version 12 Update sp3 SwEdition espos
Suse ≫ Linux Enterprise Server Version 12 Update sp3 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 12 Update sp4 SwEdition - SwPlatform sap
Suse ≫ Linux Enterprise Server Version 12 Update sp4 SwEdition espos
Suse ≫ Linux Enterprise Server Version 12 Update sp4 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 12 Update sp5 SwPlatform sap
Suse ≫ Linux Enterprise Server Version 15 SwPlatform sap
Suse ≫ Linux Enterprise Server Version 15 Update - SwEdition espos
Suse ≫ Linux Enterprise Server Version 15 Update - SwEdition ltss
Suse ≫ Linux Enterprise Server Version 15 Update sp1 SwEdition business_critical_linux SwPlatform -
Suse ≫ Linux Enterprise Server Version 15 Update sp1 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 15 Update sp2 SwEdition business_critical_linux SwPlatform -
Suse ≫ Linux Enterprise Server Version 15 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 15 Update sp3
Suse ≫ Linux Enterprise Server Version 15 Update sp4
Hp ≫ Helion Openstack Version 8.0
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Fedoraproject ≫ Fedora Version 36
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.427
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://wiki.robotz.com/index.php/Linux_CIFS_Utils_and_Samba
Third Party Advisory
https://bugzilla.samba.org/show_bug.cgi?id=15025
Vendor Advisory
Issue Tracking
Permissions Required
https://bugzilla.suse.com/show_bug.cgi?id=1197216
Patch
Third Party Advisory
Issue Tracking
https://github.com/piastry/cifs-utils/pull/7
Patch
Third Party Advisory
Issue Tracking
https://github.com/piastry/cifs-utils/pull/7/commits/955fb147e97a6a74e1aaa65766de91e2c1479765
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2022/05/msg00020.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5WBOLMANBYJILXQKRRK7OCR774PXJAYY/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXKZLJYJJEC3TIBFLXUORRMZUKG5W676/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QIYZ4L6SLSYJQ446VJAO2VGAESURQNSP/
https://security.gentoo.org/glsa/202311-05
https://www.debian.org/security/2022/dsa-5157
Third Party Advisory