Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 27 Apr 2022 09:45:54 +0200
From: Marcus Meissner <meissner@...e.de>
To: OSS Security List <oss-security@...ts.openwall.com>
Subject: CVE-2022-27239: cifs-utils mount.cifs buffer overflow in ip parameter

Hi,

A buffer overflow in mounts.cifs commandline parameter ip= handling
was just fixed/published.

CVE-2022-27239

https://bugzilla.suse.com/show_bug.cgi?id=1197216
https://github.com/piastry/cifs-utils/pull/7
https://github.com/piastry/cifs-utils/pull/7/commits/955fb147e97a6a74e1aaa65766de91e2c1479765

(mounts.cifs is usually setuid-root)

This was reported by Jeffrey Bencteux <jbe@...rosec.com> to samba security.

Both -fstack-protector and -D_FORTIFY_SOURCE=2 overflow protections are catching it.

Ciao, Marcus

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.