CVE-2022-27239

In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
Affected Products (NVD)
VendorProductVersion
sambacifs-utils
𝑥
< 6.15
debiandebian_linux
9.0
debiandebian_linux
10.0
debiandebian_linux
11.0
susecaas_platform
4.0
suseenterprise_storage
6.0
suseenterprise_storage
7.0
suselinux_enterprise_point_of_service
11.0:sp3
suselinux_enterprise_storage
7.1
susemanager_proxy
4.1
susemanager_proxy
4.2
susemanager_proxy
4.3
susemanager_retail_branch_server
4.1
susemanager_retail_branch_server
4.2
susemanager_retail_branch_server
4.3
susemanager_server
4.1
susemanager_server
4.2
susemanager_server
4.3
suseopenstack_cloud
8.0
suseopenstack_cloud
9.0
suseopenstack_cloud_crowbar
8.0
suseopenstack_cloud_crowbar
9.0
suselinux_enterprise_high_performance_computing
12.0:sp5
suselinux_enterprise_high_performance_computing
15.0
suselinux_enterprise_high_performance_computing
15.0:sp1
suselinux_enterprise_high_performance_computing
15.0:sp1
suselinux_enterprise_high_performance_computing
15.0:sp2
suselinux_enterprise_high_performance_computing
15.0:sp2
suselinux_enterprise_high_performance_computing
15.0:sp3
suselinux_enterprise_high_performance_computing
15.0:sp4
suselinux_enterprise_micro
5.2
suselinux_enterprise_micro
5.2
suselinux_enterprise_real_time
15.0:sp2
hphelion_openstack
8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cifs-utils
bookworm
2:7.0-2
fixed
bullseye
2:6.11-3.1+deb11u2
fixed
bullseye (security)
2:6.11-3.1+deb11u1
fixed
sid
2:7.0-2.1
fixed
trixie
2:7.0-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cifs-utils
bionic
Fixed 2:6.8-1ubuntu1.2
released
focal
Fixed 2:6.9-1ubuntu0.2
released
impish
Fixed 2:6.11-3.1ubuntu0.1
released
jammy
Fixed 2:6.14-1ubuntu0.1
released
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
needed
xenial
needed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
cifs-utils
suse enterprise desktop 15 SP3
6.9-150100.5.15.1
fixed
suse enterprise desktop 15 SP4
6.15-150400.3.6.1
fixed
suse enterprise desktop 15 SP5
6.15-150400.3.6.1
fixed
suse enterprise desktop 15 SP6
6.15-150400.3.6.1
fixed
suse enterprise desktop 15 SP7
6.15-150400.3.6.1
fixed
suse enterprise sap 15 SP1
6.9-150100.5.15.1
fixed
suse enterprise sap 15 SP2
6.9-150100.5.15.1
fixed
suse enterprise sap 15 SP3
6.9-150100.5.15.1
fixed
suse enterprise sap 15 SP4
6.15-150400.3.6.1
fixed
suse enterprise sap 15 SP5
6.15-150400.3.6.1
fixed
suse enterprise sap 15 SP6
6.15-150400.3.6.1
fixed
suse enterprise sap 15 SP7
6.15-150400.3.6.1
fixed
suse enterprise server 15
6.9-150000.3.17.1
fixed
suse enterprise server 15 SP1
6.9-150100.5.15.1
fixed
suse enterprise server 15 SP2
6.9-150100.5.15.1
fixed
suse enterprise server 15 SP3
6.9-150100.5.15.1
fixed
suse enterprise server 15 SP4
6.15-150400.3.6.1
fixed
suse enterprise server 15 SP5
6.15-150400.3.6.1
fixed
suse enterprise server 15 SP6
6.15-150400.3.6.1
fixed
suse enterprise server 15 SP7
6.15-150400.3.6.1
fixed
cifs-utils-devel
suse enterprise desktop 15 SP3
6.9-150100.5.15.1
fixed
suse enterprise desktop 15 SP4
6.15-150400.3.6.1
fixed
suse enterprise desktop 15 SP5
6.15-150400.3.6.1
fixed
suse enterprise desktop 15 SP6
6.15-150400.3.6.1
fixed
suse enterprise desktop 15 SP7
6.15-150400.3.6.1
fixed
suse enterprise sap 15 SP1
6.9-150100.5.15.1
fixed
suse enterprise sap 15 SP2
6.9-150100.5.15.1
fixed
suse enterprise sap 15 SP3
6.9-150100.5.15.1
fixed
suse enterprise sap 15 SP4
6.15-150400.3.6.1
fixed
suse enterprise sap 15 SP5
6.15-150400.3.6.1
fixed
suse enterprise sap 15 SP6
6.15-150400.3.6.1
fixed
suse enterprise sap 15 SP7
6.15-150400.3.6.1
fixed
suse enterprise server 15
6.9-150000.3.17.1
fixed
suse enterprise server 15 SP1
6.9-150100.5.15.1
fixed
suse enterprise server 15 SP2
6.9-150100.5.15.1
fixed
suse enterprise server 15 SP3
6.9-150100.5.15.1
fixed
suse enterprise server 15 SP4
6.15-150400.3.6.1
fixed
suse enterprise server 15 SP5
6.15-150400.3.6.1
fixed
suse enterprise server 15 SP6
6.15-150400.3.6.1
fixed
suse enterprise server 15 SP7
6.15-150400.3.6.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
cifs-utils
RHEL 8
0:7.0-1.el8
fixed
cifs-utils-devel
RHEL 8
0:7.0-1.el8
fixed
pam
RHEL 8
0:7.0-1.el8
fixed
References