CVE-2022-27239: Buffer Overflow
Published Apr 27, 2022
·Updated
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
Affected Software
62 affected componentsFixes available
debian/cifs-utils<=2:6.11-3.1, <=2:6.8-2, <=2:6.14-1
2:6.14-1.12:6.11-3.1+deb11u12:6.8-2+deb10u1
debian/cifs-utils
2:6.8-2+deb10u12:6.11-3.1+deb11u12:7.0-2
Samba cifs-utils<6.15
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
SUSE CaaS Platform=4.0
SUSE Enterprise Storage=6.0
SUSE Enterprise Storage=7.0
SUSE Linux Enterprise Point Of Service=11.0-sp3
SUSE Linux Enterprise Storage=7.1
SUSE Manager Proxy=4.1
SUSE Manager Proxy=4.2
SUSE Manager Proxy=4.3
SUSE Manager Retail Branch Server=4.1
SUSE Manager Retail Branch Server=4.2
SUSE Manager Retail Branch Server=4.3
SUSE Manager Server=4.1
SUSE Manager Server=4.2
SUSE Manager Server=4.3
SUSE Openstack Cloud=8.0
SUSE Openstack Cloud=9.0
SUSE OpenStack Cloud Crowbar=8.0
SUSE OpenStack Cloud Crowbar=9.0
SUSE Linux Enterprise Desktop=15-sp3
SUSE Linux Enterprise Desktop=15-sp4
SUSE Linux Enterprise High Performance Computing=12.0-sp5
SUSE Linux Enterprise High Performance Computing=15.0
SUSE Linux Enterprise High Performance Computing=15.0-sp1
SUSE Linux Enterprise High Performance Computing=15.0-sp1
SUSE Linux Enterprise High Performance Computing=15.0-sp2
SUSE Linux Enterprise High Performance Computing=15.0-sp2
SUSE Linux Enterprise High Performance Computing=15.0-sp3
SUSE Linux Enterprise High Performance Computing=15.0-sp4
SUSE Linux Enterprise Micro=5.2
SUSE Linux Enterprise Micro Rancher=5.2
SUSE Linux Enterprise Real Time=15.0-sp2
SUSE Linux Enterprise Server=11-sp3
SUSE Linux Enterprise Server=11-sp4
SUSE Linux Enterprise Server=12-sp2
SUSE Linux Enterprise Server Sap=12-sp3
SUSE Linux Enterprise Server=12-sp3
SUSE Linux Enterprise Server=12-sp3
SUSE Linux Enterprise Server=12-sp3
SUSE Linux Enterprise Server Sap=12-sp4
SUSE Linux Enterprise Server=12-sp4
SUSE Linux Enterprise Server=12-sp4
SUSE Linux Enterprise Server Sap=12-sp5
SUSE Linux Enterprise Server Sap=15
SUSE Linux Enterprise Server=15
SUSE Linux Enterprise Server=15
SUSE Linux Enterprise Server=15-sp1
SUSE Linux Enterprise Server=15-sp1
SUSE Linux Enterprise Server=15-sp2
SUSE Linux Enterprise Server=15-sp2
SUSE Linux Enterprise Server=15-sp3
SUSE Linux Enterprise Server=15-sp4
SUSE Linux Enterprise Software Development Kit=12-sp5
HP Helion Openstack=8.0
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Remediation
Patch Available
Patch Available
Event History
Apr 27, 2022
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-27239?
CVE-2022-27239 is classified as a high severity vulnerability due to the potential for local attackers to gain root privileges.
2
How do I fix CVE-2022-27239?
To fix CVE-2022-27239, update cifs-utils to version 6.15 or later.
3
Who is affected by CVE-2022-27239?
CVE-2022-27239 affects versions of cifs-utils prior to 6.15 across various Debian and SUSE Linux distributions.
4
What types of attacks can exploit CVE-2022-27239?
CVE-2022-27239 can be exploited by local attackers through a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument.
5
What is the impact of CVE-2022-27239 on systems?
The impact of CVE-2022-27239 is that it allows local attackers to execute arbitrary code with elevated privileges.