CVE-2022-27239

HIGHCVSS 7.8/10EPSS 0.56%

Last modified

CVE-2022-27239 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.

Description

In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.56%

42.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
SambaCifs-Utils< 6.15
DebianDebian Linux9.0
DebianDebian Linux10.0
DebianDebian Linux11.0
SuseCaas Platform4.0
SuseEnterprise Storage6.0
SuseEnterprise Storage7.0
SuseLinux Enterprise Point Of Service11.0Sp3
SuseLinux Enterprise Storage7.1
SuseManager Proxy4.1
SuseManager Proxy4.2
SuseManager Proxy4.3
SuseManager Retail Branch Server4.1
SuseManager Retail Branch Server4.2
SuseManager Retail Branch Server4.3
SuseManager Server4.1
SuseManager Server4.2
SuseManager Server4.3
SuseOpenstack Cloud8.0
SuseOpenstack Cloud9.0
SuseOpenstack Cloud Crowbar8.0
SuseOpenstack Cloud Crowbar9.0
SuseLinux Enterprise Desktop15Sp3
SuseLinux Enterprise High Performance Computing12.0Sp5
SuseLinux Enterprise High Performance Computing15.0
SuseLinux Enterprise Micro5.2
SuseLinux Enterprise Real Time15.0Sp2
SuseLinux Enterprise Server11Sp3
SuseLinux Enterprise Server12Sp2
SuseLinux Enterprise Server15
SuseLinux Enterprise Software Development Kit12Sp5
HpHelion Openstack8.0
FedoraprojectFedora34
FedoraprojectFedora35
FedoraprojectFedora36

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-27239?
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
How severe is CVE-2022-27239?
CVE-2022-27239 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.56% probability of exploitation in the next 30 days.
How do I fix CVE-2022-27239?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-27239?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST