NA

CVE-2022-47943

Published: 23/12/2022 Updated: 16/05/2023
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in ksmbd in the Linux kernel 5.15 up to and including 5.19 prior to 5.19.2. There is an out-of-bounds read and OOPS for SMB2_WRITE, when there is a large length in the zero DataOffset case.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: An issue was discovered in ksmbd in the Linux kernel 515 through 519 before 5192 There is an out-of-bounds read and OOPS for SMB2_WRITE, when there is a large length in the zero DataOffset case ...
out-of-bounds read memory can be written to a file, if DataOffset is 0 and Length is too large in SMB2_WRITE request of compound request in fs/ksmbd/smb2miscc can allow a remote authenticated attacker to disclose sensitive information ...