Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 34: FEDORA-2022-34de4f833d Critical: cifs-utils Buffer Overflow

fedora
Calendar Grey May 8, 2022
Dist Fedora Esm H88
An urgent update for cifs-utils on Fedora 34 resolves significant vulnerabilities that could permit unauthorized root access and compromise user privacy.
This is a security release to address the following bugs: - CVE-2022-27239: mount.cifs: fix length check for ip option parsing - CVE-2022-29869: mount.cifs: fix verbose messages on...

Summary

The SMB/CIFS protocol is a standard file sharing protocol widely deployed

on Microsoft Windows machines. This package contains tools for mounting

shares on Linux using the SMB/CIFS protocol. The tools in this package

work in conjunction with support in the kernel to allow one to mount a

SMB/CIFS share onto a client and use it as if it were a standard Linux

file system.

This is a security release to address the following bugs: - CVE-2022-27239:

mount.cifs: fix length check for ip option parsing - CVE-2022-29869: mount.cifs:

fix verbose messages on option parsing Description CVE-2022-27239: In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs

ip= command-line argument could lead to local attackers gaining root privileges.

CVE-2022-29869: cifs-utils through 6.14, with verbose logging, can cause an

information leak when a file contains = (equal sign) characters but is not a

valid credentials file. Both issues were originally reported and fixed by

Jeffrey Bencteux.

* Sat Apr 30 2022 Alexander Bokovoy - 6.15-1

- Upstream release 6.15

- CVE-2022-27239: mount.cifs: fix length check for ip option parsing

- CVE-2022-29869: mount.cifs: fix verbose messages on option parsing

- Fixes: rhbz#2080525

[ 1 ] Bug #2080525 - cifs-utils-6.15 is available

https://bugzilla.redhat.com/show_bug.cgi?id=2080525

su -c 'dnf upgrade --advisory FEDORA-2022-34de4f833d' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 34
Version: 6.15
Release: 1.fc34
URL:
Summary: Utilities for mounting and managing CIFS mounts

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here