CVE-2022-29869: Medium severity cifs utils vulnerability
Published Apr 28, 2022
·Updated
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
Affected Software
8 affected componentsFixes available
debian/cifs-utils
2:6.8-2+deb10u12:6.11-3.1+deb11u12:7.0-2
Samba cifs-utils<6.15
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Patch Available
Event History
Apr 28, 2022
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-29869?
CVE-2022-29869 is a vulnerability in cifs-utils through version 6.14 that can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
2
How does CVE-2022-29869 affect Samba Cifs-utils?
CVE-2022-29869 affects Samba Cifs-utils versions up to and excluding 6.15.
3
Which operating systems are affected by CVE-2022-29869?
CVE-2022-29869 affects Fedora 34, Fedora 35, Fedora 36, Debian Linux 9.0, Debian Linux 10.0, and Debian Linux 11.0.
4
What is the severity of CVE-2022-29869?
CVE-2022-29869 has a severity rating of 5.3 (Medium).
5
How can I fix CVE-2022-29869?
To fix CVE-2022-29869, update cifs-utils to version 2:6.8-2+deb10u1, 2:6.11-3.1+deb11u1, or 2:7.0-2.