Back

HIGH

cifs-utils: stack-based buffer overflow mount.cifs may lead to local privilege escalation to root

Published Apr 27, 2022

Description

In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.

Affected products

Remediation

Red Hat statement

The mount.cifs binary file is shipped without setuid privileges as default which prevents an attacker to gain root privileges hence lowering the flaw impact.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 27, 2022
Updated Aug 3, 2024
Reserved Mar 18, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 27, 2022