CVE-2022-47940: High severity linux kernel vulnerability
Published Dec 23, 2022
·Updated
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2write.
Affected Software
4 affected componentsFixes available
Linux Linux kernel>=5.15<5.18.8
Linux Linux kernel>=5.15<5.15.145
Linux Linux kernel>=5.16<5.18.18
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
Remediation
Event History
Dec 23, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:12 AM
Description
Dec 1, 2024
Data Sourced
via Ubuntu·03:59 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-47940?
CVE-2022-47940 has been categorized as high severity due to the lack of length validation in the smb2_write function.
2
How do I fix CVE-2022-47940?
To fix CVE-2022-47940, upgrade your Linux kernel to version 5.18.18 or later.
3
Which Linux kernel versions are affected by CVE-2022-47940?
CVE-2022-47940 affects Linux kernel versions from 5.15 through 5.18 before 5.18.18.
4
What are the potential impacts of CVE-2022-47940?
Exploitation of CVE-2022-47940 could lead to data corruption or denial of service conditions in the affected systems.
5
Is CVE-2022-47940 related to SMB protocol vulnerabilities?
Yes, CVE-2022-47940 relates specifically to vulnerabilities in the SMB2 protocol implementation within the ksmbd module.