CVE-2022-47940 — Out-of-bounds Read in Kernel
Severity
8.1HIGHNVD
OSV5.5
EPSS
1.5%
top 18.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 23
Latest updateFeb 15
Description
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 2.8 | Impact: 5.2
Affected Packages6 packages
Patches
🔴Vulnerability Details
6OSV▶
linux-aws, linux-aws-5.15, linux-azure-fde, linux-gcp, linux-gcp-5.15, linux-intel-iotg vulnerabilities↗2023-02-15
OSV▶
linux, linux-azure, linux-azure-5.15, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle, linux-oracle-5.15, linux-raspi vulnerabilities↗2023-02-09
📋Vendor Advisories
7Red Hat▶
kernel: smb2_write() fails to validate user supplied data which can result in out-of-bounds read↗2022-12-22