CVE-2022-27239

In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
VendorProductVersion
sambacifs-utils
𝑥
< 6.15
debiandebian_linux
9.0
debiandebian_linux
10.0
debiandebian_linux
11.0
susecaas_platform
4.0
suseenterprise_storage
6.0
suseenterprise_storage
7.0
suselinux_enterprise_point_of_service
11.0:sp3
suselinux_enterprise_storage
7.1
susemanager_proxy
4.1
susemanager_proxy
4.2
susemanager_proxy
4.3
susemanager_retail_branch_server
4.1
susemanager_retail_branch_server
4.2
susemanager_retail_branch_server
4.3
susemanager_server
4.1
susemanager_server
4.2
susemanager_server
4.3
suseopenstack_cloud
8.0
suseopenstack_cloud
9.0
suseopenstack_cloud_crowbar
8.0
suseopenstack_cloud_crowbar
9.0
suselinux_enterprise_high_performance_computing
12.0:sp5
suselinux_enterprise_high_performance_computing
15.0
suselinux_enterprise_high_performance_computing
15.0:sp1
suselinux_enterprise_high_performance_computing
15.0:sp1
suselinux_enterprise_high_performance_computing
15.0:sp2
suselinux_enterprise_high_performance_computing
15.0:sp2
suselinux_enterprise_high_performance_computing
15.0:sp3
suselinux_enterprise_high_performance_computing
15.0:sp4
suselinux_enterprise_micro
5.2
suselinux_enterprise_micro
5.2
suselinux_enterprise_real_time
15.0:sp2
hphelion_openstack
8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cifs-utils
bullseye
2:6.11-3.1+deb11u2
fixed
bullseye (security)
2:6.11-3.1+deb11u1
fixed
bookworm
2:7.0-2
fixed
sid
2:7.0-2.1
fixed
trixie
2:7.0-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cifs-utils
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
Fixed 2:6.14-1ubuntu0.1
released
impish
Fixed 2:6.11-3.1ubuntu0.1
released
focal
Fixed 2:6.9-1ubuntu0.2
released
bionic
Fixed 2:6.8-1ubuntu1.2
released
xenial
needed
trusty
needed
References