PT-2022-6038 · Linux+2 · Linux Kernel+2
Arnaud Gatignol
+4
·
Published
2022-08-04
·
Updated
2023-05-16
·
CVE-2022-47942
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 5.15 through 5.19 before 5.19.2
Description
The issue is related to a heap-based buffer overflow in the Linux kernel's ksmbd subsystem, specifically in the set ntacl dacl function. This overflow is connected to the use of
SMB2 QUERY INFO HE after a malformed SMB2 SET INFO HE command. The exploitation of this issue could allow a remote attacker to execute arbitrary code.Recommendations
For Linux kernel versions 5.15 through 5.19 before 5.19.2, update to version 5.19.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the
set ntacl dacl function and the SMB2 QUERY INFO HE and SMB2 SET INFO HE commands until a patch is applied.Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linux Kernel