Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-47942
HistoryDec 23, 2022 - 12:00 a.m.

CVE-2022-47942

2022-12-2300:00:00
ubuntu.com
ubuntu.com
28
cve-2022-47942
ksmbd
smb2_query_info_he
set_ntacl_dacl

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.006 Low

EPSS

Percentile

77.9%

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19
before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl,
related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE
command.

Notes

Author Note
sbeattie needs ksmbd-tools installed to enable the service, which is not installed by default.
OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchlinux< 5.15.0-53.59UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1023.27UNKNOWN
ubuntu20.04noarchlinux-aws-5.15< 5.15.0-1023.27~20.04.1UNKNOWN
ubuntu22.04noarchlinux-azure< 5.15.0-1023.29UNKNOWN
ubuntu20.04noarchlinux-azure-5.15< 5.15.0-1023.29~20.04.1UNKNOWN
ubuntu22.04noarchlinux-azure-fde< 5.15.0-1024.30.1UNKNOWN
ubuntu20.04noarchlinux-azure-fde-5.15< 5.15.0-1029.36~20.04.1.1UNKNOWN
ubuntu22.04noarchlinux-gcp< 5.15.0-1022.29UNKNOWN
ubuntu20.04noarchlinux-gcp-5.15< 5.15.0-1022.29~20.04.1UNKNOWN
ubuntu22.04noarchlinux-gke< 5.15.0-1020.25UNKNOWN
Rows per page:
1-10 of 231

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.006 Low

EPSS

Percentile

77.9%