NA

CVE-2022-47942

Published: 23/12/2022 Updated: 16/05/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in ksmbd in the Linux kernel 5.15 up to and including 5.19 prior to 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: An issue was discovered in ksmbd in the Linux kernel 515 through 519 before 5192 There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command ...
heap-overflow in set_ntacl_dacl() when setting a malformed file attribute under the label `securityNTACL` using SMB2_SET_INFO_HE followed by SMB2_QUERY_INFO_HE ...