NA

CVE-2022-47940

Published: 23/12/2022 Updated: 30/12/2022
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in ksmbd in the Linux kernel 5.15 up to and including 5.18 prior to 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: An issue was discovered in ksmbd in the Linux kernel 515 through 518 before 51818 fs/ksmbd/smb2pduc lacks length validation in the non-padding case in smb2_write ...
smb2_write() and smb2_write_pipe do not avlidate the length when no padding is used ...