CVE-2022-27239
published 2022-04-27CVE-2022-27239: In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.56%
42.8th percentile
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cifs-utils | < cifs-utils 2:6.14-1.1 (bookworm) | cifs-utils 2:6.14-1.1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| hp | helion_openstack | — | — |
| msrc | cbl2_cifs-utils_6.14-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_cifs-utils_6.8-6_on_cbl_mariner_1.0 | — | — |
| samba | cifs-utils | < 6.15 | 6.15 |
| samba | cifs-utils | >= 0 < 2:6.11-3.1+deb11u1 | 2:6.11-3.1+deb11u1 |
| samba | cifs-utils | >= 0 < 2:6.14-1.1 | 2:6.14-1.1 |
| samba | cifs-utils | >= 0 < 2:6.14-1.1 | 2:6.14-1.1 |
| samba | cifs-utils | >= 0 < 2:6.14-1.1 | 2:6.14-1.1 |
| samba | cifs-utils | >= 0 < 2:6.8-1ubuntu1.2 | 2:6.8-1ubuntu1.2 |
| samba | cifs-utils | >= 0 < 2:6.9-1ubuntu0.2 | 2:6.9-1ubuntu0.2 |
| samba | cifs-utils | >= 0 < 2:6.14-1ubuntu0.1 | 2:6.14-1ubuntu0.1 |
| samba | cifs-utils | >= 0 < 2:6.0-1ubuntu2+esm1 | 2:6.0-1ubuntu2+esm1 |
| samba | cifs-utils | >= 0 < 2:6.4-1ubuntu1.1+esm1 | 2:6.4-1ubuntu1.1+esm1 |
| suse | caas_platform | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
cifs-utils vulnerabilities
osv·2025-08-07·CVSS 7.0
CVE-2020-14342 [HIGH] cifs-utils vulnerabilities
cifs-utils vulnerabilities
Aurélien Aptel discovered that cifs-utils invoked a shell when requesting a
password. In certain environments, a local attacker could possibly use this
issue to escalate privileges. (CVE-2020-14342)
It was discovered that cifs-utils incorrectly used host credentials when
mounting a krb5 CIFS file system from within a container. An attacker
inside a container could possibly use this issue to obtain access to
sensitive information. (CVE-2021-20208)
It was discovered that cifs-utils incorrectly handled certain command-line
arguments. A local attacker could possibly use this issue to obtain root
privileges. (CVE-2022-27239)
It was discovered that cifs-utils incorrectly handled verbose logging. A
local attacker could possibly use this issue to obtain sensitive
inf
OSV
cifs-utils vulnerabilities
osv·2022-06-02·CVSS 7.0
CVE-2020-14342 [HIGH] cifs-utils vulnerabilities
cifs-utils vulnerabilities
Aurélien Aptel discovered that cifs-utils invoked a shell when requesting a
password. In certain environments, a local attacker could possibly use this
issue to escalate privileges. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-14342)
It was discovered that cifs-utils incorrectly used host credentials when
mounting a krb5 CIFS file system from within a container. An attacker
inside a container could possibly use this issue to obtain access to
sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu
20.04 LTS. (CVE-2021-20208)
It was discovered that cifs-utils incorrectly handled certain command-line
arguments. A local attacker could possibly use this issue to obtain root
privileges. (CVE-2022-27239)
It was discov
GHSA
GHSA-mhc8-vv44-hh59: In cifs-utils through 6
ghsa_unreviewed·2022-04-28
CVE-2022-27239 [HIGH] CWE-787 GHSA-mhc8-vv44-hh59: In cifs-utils through 6
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
OSV
CVE-2022-27239: In cifs-utils through 6
osv·2022-04-27·CVSS 7.8
CVE-2022-27239 [HIGH] CVE-2022-27239: In cifs-utils through 6
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
Ubuntu
cifs-utils vulnerabilities
vendor_ubuntu·2025-08-07·CVSS 4.4
CVE-2021-20208 [MEDIUM] cifs-utils vulnerabilities
Title: cifs-utils vulnerabilities
Summary: Several security issues were fixed in cifs-utils.
Aurélien Aptel discovered that cifs-utils invoked a shell when requesting a
password. In certain environments, a local attacker could possibly use this
issue to escalate privileges. (CVE-2020-14342)
It was discovered that cifs-utils incorrectly used host credentials when
mounting a krb5 CIFS file system from within a container. An attacker
inside a container could possibly use this issue to obtain access to
sensitive information. (CVE-2021-20208)
It was discovered that cifs-utils incorrectly handled certain command-line
arguments. A local attacker could possibly use this issue to obtain root
privileges. (CVE-2022-27239)
It was discovered that cifs-utils incorrectly handled verbose logging. A
l
Ubuntu
cifs-utils vulnerabilities
vendor_ubuntu·2022-06-02·CVSS 4.4
CVE-2020-14342 [MEDIUM] cifs-utils vulnerabilities
Title: cifs-utils vulnerabilities
Summary: Several security issues were fixed in cifs-utils.
Aurélien Aptel discovered that cifs-utils invoked a shell when requesting a
password. In certain environments, a local attacker could possibly use this
issue to escalate privileges. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-14342)
It was discovered that cifs-utils incorrectly used host credentials when
mounting a krb5 CIFS file system from within a container. An attacker
inside a container could possibly use this issue to obtain access to
sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu
20.04 LTS. (CVE-2021-20208)
It was discovered that cifs-utils incorrectly handled certain command-line
arguments. A local attacker could possibly use th
Red Hat
cifs-utils: stack-based buffer overflow mount.cifs may lead to local privilege escalation to root
vendor_redhat·2022-04-27·CVSS 7.8
CVE-2022-27239 [HIGH] CWE-787 cifs-utils: stack-based buffer overflow mount.cifs may lead to local privilege escalation to root
cifs-utils: stack-based buffer overflow mount.cifs may lead to local privilege escalation to root
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
A stack-based buffer overflow issue was found in cifs-utils. Parsing the mount.cifs ip command-line argument can lead to local attackers gaining root privileges.
Statement: The mount.cifs binary file is shipped without setuid privileges as default which prevents an attacker to gain root privileges hence lowering the flaw impact.
Package: cifs-utils (Red Hat Enterprise Linux 6) - Out of support scope
Package: cifs-utils (Red Hat Enterprise Linux 7) - Will not fix
Package: cifs-utils (Red Hat Enterprise Linux 9) - Will not fi
Microsoft
In cifs-utils through 6.14 a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
vendor_msrc·2022-04-12·CVSS 7.8
CVE-2022-27239 [HIGH] CWE-787 In cifs-utils through 6.14 a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
In cifs-utils through 6.14 a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mar
Debian
CVE-2022-27239: cifs-utils - In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount...
vendor_debian·2022·CVSS 7.8
CVE-2022-27239 [HIGH] CVE-2022-27239: cifs-utils - In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount...
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
Scope: local
bookworm: resolved (fixed in 2:6.14-1.1)
bullseye: resolved (fixed in 2:6.11-3.1+deb11u1)
forky: resolved (fixed in 2:6.14-1.1)
sid: resolved (fixed in 2:6.14-1.1)
trixie: resolved (fixed in 2:6.14-1.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://wiki.robotz.com/index.php/Linux_CIFS_Utils_and_Sambahttps://bugzilla.samba.org/show_bug.cgi?id=15025https://bugzilla.suse.com/show_bug.cgi?id=1197216https://github.com/piastry/cifs-utils/pull/7https://github.com/piastry/cifs-utils/pull/7/commits/955fb147e97a6a74e1aaa65766de91e2c1479765https://lists.debian.org/debian-lts-announce/2022/05/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5WBOLMANBYJILXQKRRK7OCR774PXJAYY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXKZLJYJJEC3TIBFLXUORRMZUKG5W676/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QIYZ4L6SLSYJQ446VJAO2VGAESURQNSP/https://security.gentoo.org/glsa/202311-05https://www.debian.org/security/2022/dsa-5157http://wiki.robotz.com/index.php/Linux_CIFS_Utils_and_Sambahttps://bugzilla.samba.org/show_bug.cgi?id=15025https://bugzilla.suse.com/show_bug.cgi?id=1197216https://github.com/piastry/cifs-utils/pull/7https://github.com/piastry/cifs-utils/pull/7/commits/955fb147e97a6a74e1aaa65766de91e2c1479765https://lists.debian.org/debian-lts-announce/2022/05/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5WBOLMANBYJILXQKRRK7OCR774PXJAYY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXKZLJYJJEC3TIBFLXUORRMZUKG5W676/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QIYZ4L6SLSYJQ446VJAO2VGAESURQNSP/https://security.gentoo.org/glsa/202311-05https://www.debian.org/security/2022/dsa-5157
2022-04-27
Published