ALAS2-2023-1978

Related Vulnerabilities: CVE-2022-27239  

A stack-based buffer overflow issue was found in pifs-utils. Parsing the mount.cifs ip command-line argument can lead to local attackers gaining root privileges. (CVE-2022-27239)

ALAS2-2023-1978


Amazon Linux 2 Security Advisory: ALAS-2023-1978
Advisory Release Date: 2023-03-02 22:35 Pacific
Advisory Updated Date: 2023-03-07 00:20 Pacific
Severity: Important

Issue Overview:

A stack-based buffer overflow issue was found in pifs-utils. Parsing the mount.cifs ip command-line argument can lead to local attackers gaining root privileges. (CVE-2022-27239)


Affected Packages:

cifs-utils


Issue Correction:
Run yum update cifs-utils to update your system.

New Packages:
aarch64:
    cifs-utils-6.2-10.amzn2.0.3.aarch64
    cifs-utils-devel-6.2-10.amzn2.0.3.aarch64
    cifs-utils-debuginfo-6.2-10.amzn2.0.3.aarch64

i686:
    cifs-utils-6.2-10.amzn2.0.3.i686
    cifs-utils-devel-6.2-10.amzn2.0.3.i686
    cifs-utils-debuginfo-6.2-10.amzn2.0.3.i686

src:
    cifs-utils-6.2-10.amzn2.0.3.src

x86_64:
    cifs-utils-6.2-10.amzn2.0.3.x86_64
    cifs-utils-devel-6.2-10.amzn2.0.3.x86_64
    cifs-utils-debuginfo-6.2-10.amzn2.0.3.x86_64