cbcvebase.
CVE-2022-27239
published 2022-04-27

CVE-2022-27239: In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
debiancifs-utils< cifs-utils 2:6.14-1.1 (bookworm)cifs-utils 2:6.14-1.1 (bookworm)
debiandebian_linux
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
hphelion_openstack
msrccbl2_cifs-utils_6.14-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_cifs-utils_6.8-6_on_cbl_mariner_1.0
sambacifs-utils< 6.156.15
sambacifs-utils>= 0 < 2:6.11-3.1+deb11u12:6.11-3.1+deb11u1
sambacifs-utils>= 0 < 2:6.14-1.12:6.14-1.1
sambacifs-utils>= 0 < 2:6.14-1.12:6.14-1.1
sambacifs-utils>= 0 < 2:6.14-1.12:6.14-1.1
sambacifs-utils>= 0 < 2:6.8-1ubuntu1.22:6.8-1ubuntu1.2
sambacifs-utils>= 0 < 2:6.9-1ubuntu0.22:6.9-1ubuntu0.2
sambacifs-utils>= 0 < 2:6.14-1ubuntu0.12:6.14-1ubuntu0.1
sambacifs-utils>= 0 < 2:6.0-1ubuntu2+esm12:6.0-1ubuntu2+esm1
sambacifs-utils>= 0 < 2:6.4-1ubuntu1.1+esm12:6.4-1ubuntu1.1+esm1
susecaas_platform

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH