Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-47942

Опубликовано: 22 дек. 2022
Источник: redhat
CVSS3: 8.5
EPSS Низкий

Описание

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command.

Отчет

There was no shipped kernel version that was seen affected by this problem. These files are not built in our source code. See https://access.redhat.com/solutions/6991749 for more information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2155946kernel: improper validation user-supplied data could lead in heap buffer overflow which can result in RCE

EPSS

Процентиль: 37%
0.00157
Низкий

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 3 лет назад

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command.

CVSS3: 8.8
nvd
около 3 лет назад

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command.

CVSS3: 8.8
msrc
около 3 лет назад

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command.

CVSS3: 8.8
debian
около 3 лет назад

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 ...

CVSS3: 8.8
github
около 3 лет назад

An issue was discovered in ksmbd in the Linux kernel before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command.

EPSS

Процентиль: 37%
0.00157
Низкий

8.5 High

CVSS3