Lucene search

K
cve[email protected]CVE-2022-47942
HistoryDec 23, 2022 - 4:15 p.m.

CVE-2022-47942

2022-12-2316:15:12
CWE-787
web.nvd.nist.gov
46
cve-2022-47942
ksmbd
linux kernel
buffer overflow
smb2
nvd

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.4 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

77.9%

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command.

Affected configurations

NVD
Node
linuxlinux_kernelRange5.155.15.62
OR
linuxlinux_kernelRange5.165.18.18
OR
linuxlinux_kernelRange5.195.19.2

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.4 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

77.9%