Lucene search

K
cveMitreCVE-2022-27239
HistoryApr 27, 2022 - 2:15 p.m.

CVE-2022-27239

2022-04-2714:15:09
CWE-787
mitre
web.nvd.nist.gov
119
6
cve-2022-27239
cifs-utils
buffer overflow
local attack
root privilege escalation

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

40.2%

In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.

Affected configurations

Nvd
Node
sambacifs-utilsRange<6.15
Node
debiandebian_linuxMatch9.0
OR
debiandebian_linuxMatch10.0
OR
debiandebian_linuxMatch11.0
Node
susecaas_platformMatch4.0
OR
suseenterprise_storageMatch6.0
OR
suseenterprise_storageMatch7.0
OR
suselinux_enterprise_point_of_serviceMatch11.0sp3
OR
suselinux_enterprise_storageMatch7.1
OR
susemanager_proxyMatch4.1
OR
susemanager_proxyMatch4.2
OR
susemanager_proxyMatch4.3
OR
susemanager_retail_branch_serverMatch4.1
OR
susemanager_retail_branch_serverMatch4.2
OR
susemanager_retail_branch_serverMatch4.3
OR
susemanager_serverMatch4.1
OR
susemanager_serverMatch4.2
OR
susemanager_serverMatch4.3
OR
suseopenstack_cloudMatch8.0
OR
suseopenstack_cloudMatch9.0
OR
suseopenstack_cloud_crowbarMatch8.0
OR
suseopenstack_cloud_crowbarMatch9.0
OR
suselinux_enterprise_desktopMatch15sp3
OR
suselinux_enterprise_desktopMatch15sp4
OR
suselinux_enterprise_high_performance_computingMatch12.0sp5-
OR
suselinux_enterprise_high_performance_computingMatch15.0-ltss
OR
suselinux_enterprise_high_performance_computingMatch15.0sp1espos
OR
suselinux_enterprise_high_performance_computingMatch15.0sp1ltss
OR
suselinux_enterprise_high_performance_computingMatch15.0sp2espos
OR
suselinux_enterprise_high_performance_computingMatch15.0sp2ltss
OR
suselinux_enterprise_high_performance_computingMatch15.0sp3-
OR
suselinux_enterprise_high_performance_computingMatch15.0sp4-
OR
suselinux_enterprise_microMatch5.2-
OR
suselinux_enterprise_microMatch5.2rancher
OR
suselinux_enterprise_real_timeMatch15.0sp2
OR
suselinux_enterprise_serverMatch11sp3-
OR
suselinux_enterprise_serverMatch11sp4ltss
OR
suselinux_enterprise_serverMatch12sp2business_critical_linux-
OR
suselinux_enterprise_serverMatch12sp3sap
OR
suselinux_enterprise_serverMatch12sp3business_critical_linux-
OR
suselinux_enterprise_serverMatch12sp3espos
OR
suselinux_enterprise_serverMatch12sp3ltss
OR
suselinux_enterprise_serverMatch12sp4-sap
OR
suselinux_enterprise_serverMatch12sp4espos
OR
suselinux_enterprise_serverMatch12sp4ltss
OR
suselinux_enterprise_serverMatch12sp5sap
OR
suselinux_enterprise_serverMatch15sap
OR
suselinux_enterprise_serverMatch15-espos
OR
suselinux_enterprise_serverMatch15-ltss
OR
suselinux_enterprise_serverMatch15sp1business_critical_linux-
OR
suselinux_enterprise_serverMatch15sp1ltss
OR
suselinux_enterprise_serverMatch15sp2business_critical_linux-
OR
suselinux_enterprise_serverMatch15sp2ltss
OR
suselinux_enterprise_serverMatch15sp3
OR
suselinux_enterprise_serverMatch15sp4
OR
suselinux_enterprise_software_development_kitMatch12sp5
Node
hphelion_openstackMatch8.0
Node
fedoraprojectfedoraMatch34
OR
fedoraprojectfedoraMatch35
OR
fedoraprojectfedoraMatch36
VendorProductVersionCPE
sambacifs-utils*cpe:2.3:a:samba:cifs-utils:*:*:*:*:*:*:*:*
debiandebian_linux9.0cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
debiandebian_linux10.0cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
debiandebian_linux11.0cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
susecaas_platform4.0cpe:2.3:a:suse:caas_platform:4.0:*:*:*:*:*:*:*
suseenterprise_storage6.0cpe:2.3:a:suse:enterprise_storage:6.0:*:*:*:*:*:*:*
suseenterprise_storage7.0cpe:2.3:a:suse:enterprise_storage:7.0:*:*:*:*:*:*:*
suselinux_enterprise_point_of_service11.0cpe:2.3:a:suse:linux_enterprise_point_of_service:11.0:sp3:*:*:*:*:*:*
suselinux_enterprise_storage7.1cpe:2.3:a:suse:linux_enterprise_storage:7.1:*:*:*:*:*:*:*
susemanager_proxy4.1cpe:2.3:a:suse:manager_proxy:4.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 601

Social References

More

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

40.2%