CVE-2022-27239
Summary
| CVE | CVE-2022-27239 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-27 14:15:00 UTC |
| Updated | 2023-11-24 15:15:00 UTC |
| Description | In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 35 Update: cifs-utils-6.15-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| mount.cifs: two bug fixes by ddiss · Pull Request #7 · piastry/cifs-utils · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 36 Update: cifs-utils-6.15-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| mount.cifs: two bug fixes by ddiss · Pull Request #7 · piastry/cifs-utils · GitHub |
MISC |
github.com |
|
| Linux CIFS Utils and Samba - Free Knowledge Base- The DUCK Project: information for everyone |
MISC |
wiki.robotz.com |
|
| LinuxCIFS utils: Multiple Vulnerabilities (GLSA 202311-05) — Gentoo security |
|
security.gentoo.org |
|
| [SECURITY] Fedora 34 Update: cifs-utils-6.15-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Bug Access Denied |
MISC |
bugzilla.samba.org |
|
| Bug 1197216 – VUL-0: CVE-2022-27239: cifs-utils: buffer overflow in commandline ip= handling |
MISC |
bugzilla.suse.com |
|
| [SECURITY] Fedora 34 Update: cifs-utils-6.15-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: cifs-utils-6.15-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: cifs-utils-6.15-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 3009-1] cifs-utils security update |
MLIST |
lists.debian.org |
|
| Debian -- Security Information -- DSA-5157-1 cifs-utils |
DEBIAN |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179289 Debian Security Update for cifs-utils (DLA 3009-1)
- 179349 Debian Security Update for cifs-utils (DSA 5157-1)
- 183617 Debian Security Update for cifs-utils (CVE-2022-27239)
- 198816 Ubuntu Security Notification for cifs-utils Vulnerabilities (USN-5459-1)
- 282665 Fedora Security Update for cifs (FEDORA-2022-34de4f833d)
- 282666 Fedora Security Update for cifs (FEDORA-2022-7fda04ab5a)
- 282720 Fedora Security Update for cifs (FEDORA-2022-eb2d3ca94d)
- 354381 Amazon Linux Security Advisory for cifs-utils : ALAS2022-2022-089
- 354469 Amazon Linux Security Advisory for cifs-utils : ALAS2022-2022-204
- 354785 Amazon Linux Security Advisory for cifs-utils : ALAS2-2023-1977
- 354805 Amazon Linux Security Advisory for cifs-utils : ALAS2-2023-1978
- 354811 Amazon Linux Security Advisory for cifs-utils : ALAS-2023-1698
- 357248 Amazon Linux Security Advisory for cifs-utils : ALAS2023-2024-530
- 502210 Alpine Linux Security Update for cifs-utils
- 503880 Alpine Linux Security Update for cifs-utils
- 671838 EulerOS Security Update for cifs-utils (EulerOS-SA-2022-1883)
- 671895 EulerOS Security Update for cifs-utils (EulerOS-SA-2022-1923)
- 671908 EulerOS Security Update for cifs-utils (EulerOS-SA-2022-1960)
- 671936 EulerOS Security Update for cifs-utils (EulerOS-SA-2022-1990)
- 671965 EulerOS Security Update for cifs-utils (EulerOS-SA-2022-2127)
- 671971 EulerOS Security Update for cifs-utils (EulerOS-SA-2022-2152)
- 672234 EulerOS Security Update for cifs-utils (EulerOS-SA-2022-2602)
- 710788 Gentoo Linux LinuxCIFS utils Multiple Vulnerabilities (GLSA 202311-05)
- 752077 SUSE Enterprise Linux Security Update for cifs-utils (SUSE-SU-2022:1428-1)
- 752078 SUSE Enterprise Linux Security Update for cifs-utils (SUSE-SU-2022:1429-1)
- 752079 SUSE Enterprise Linux Security Update for cifs-utils (SUSE-SU-2022:1430-1)
- 752082 SUSE Enterprise Linux Security Update for cifs-utils (SUSE-SU-2022:1427-1)
- 752347 SUSE Enterprise Linux Security Update for cifs-utils (SUSE-SU-2022:2378-1)
- 753220 SUSE Enterprise Linux Security Update for cifs-utils (SUSE-SU-2022:14951-1)
- 901286 Common Base Linux Mariner (CBL-Mariner) Security Update for cifs-utils (9609)
- 901645 Common Base Linux Mariner (CBL-Mariner) Security Update for cifs-utils (9587)
- 902033 Common Base Linux Mariner (CBL-Mariner) Security Update for cifs-utils (9609-1)
- 902080 Common Base Linux Mariner (CBL-Mariner) Security Update for cifs-utils (9587-1)