Vulnerability CVE-2022-27239: Information
Description
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
cifs-utils | sisyphus | 6.15-alt1 | 7.1-alt2 | ALT-PU-2022-2522-1 | 306005 | Fixed |
cifs-utils | sisyphus_e2k | 6.15-alt1 | 7.1-alt2 | ALT-PU-2022-5942-1 | - | Fixed |
cifs-utils | sisyphus_riscv64 | 6.15-alt1 | 7.1-alt2 | ALT-PU-2022-5891-1 | - | Fixed |
cifs-utils | p10 | 6.15-alt1 | 7.1-alt1 | ALT-PU-2022-2576-1 | 306006 | Fixed |
cifs-utils | p10_e2k | 6.15-alt1 | 7.1-alt1 | ALT-PU-2022-6096-1 | - | Fixed |
cifs-utils | c10f2 | 6.15-alt1 | 6.15-alt1 | ALT-PU-2022-2576-1 | 306006 | Fixed |
cifs-utils | c9f2 | 6.15-alt1 | 6.15-alt1 | ALT-PU-2022-2563-1 | 306007 | Fixed |
cifs-utils | p11 | 6.15-alt1 | 7.1-alt2 | ALT-PU-2022-2522-1 | 306005 | Fixed |