CVE-2022-47943Out-of-bounds Read in Kernel

CWE-125Out-of-bounds Read6 documents6 sources
Severity
8.1HIGHNVD
EPSS
1.7%
top 17.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 23

Description

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is an out-of-bounds read and OOPS for SMB2_WRITE, when there is a large length in the zero DataOffset case.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages6 packages

NVDlinux/linux_kernel5.155.15.62+2
Debianlinux/linux_kernel< 5.19.6-1+2
debiandebian/linux< linux 5.19.6-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2022-47943: An issue was discovered in ksmbd in the Linux kernel 52022-12-23
GHSA
GHSA-m847-mpgv-7mwr: An issue was discovered in ksmbd in the Linux kernel before 52022-12-23

📋Vendor Advisories

3
Red Hat
kernel: large length in the zero DataOffset case in smb2_write() processing could result in out-of-bounds read2022-12-22
Microsoft
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is an out-of-bounds read and OOPS for SMB2_WRITE when there is a large length in the zero DataOffset case.2022-12-13
Debian
CVE-2022-47943: linux - An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5....2022