CVE-2022-47939
CVSS V2 None
CVSS V3 None
Description
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT.
Overview
- CVE ID
- CVE-2022-47939
- Assigner
- cve@mitre.org
- Vulnerability Status
- Undergoing Analysis
- Published Version
- 2022-12-23T16:15:12
- Last Modified Date
- 2023-03-30T23:15:06
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 1 | OR | 5.15 | 5.19.2 |
References
Reference URL | Reference Tags |
---|---|
http://www.openwall.com/lists/oss-security/2022/12/23/10 | Mailing List Third Party Advisory |
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19.2 | Mailing List Patch Vendor Advisory |
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cf6531d98190fa2cf92a6d8bbc8af0a4740a223c | Mailing List Patch Vendor Advisory |
https://github.com/torvalds/linux/commit/cf6531d98190fa2cf92a6d8bbc8af0a4740a223c | Patch Third Party Advisory |
https://www.secpod.com/blog/zero-day-server-message-block-smb-server-in-linux-kernel-5-15-has-a-critical-vulnerability-patch-ksmbd-immediately/ | |
https://www.zerodayinitiative.com/advisories/ZDI-22-1690/ | Third Party Advisory VDB Entry |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2022-47939 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-47939 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-12-23 16:18:46 | Added to TrackCVE | |||
2022-12-23 17:15:45 | 2022-12-23T16:52:12 | CVE Modified Date | updated | |
2022-12-23 17:15:45 | Received | Awaiting Analysis | Vulnerability Status | updated |
2022-12-23 20:15:30 | 2022-12-23T19:15:12 | CVE Modified Date | updated | |
2022-12-23 20:15:32 | References | updated | ||
2022-12-25 23:15:27 | 2022-12-25T23:15:10 | CVE Modified Date | updated | |
2022-12-25 23:15:27 | An issue was discovered in ksmbd in the Linux kernel before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT. | An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT. | Description | updated |
2022-12-27 17:15:17 | Awaiting Analysis | Undergoing Analysis | Vulnerability Status | updated |
2022-12-30 16:17:24 | 2022-12-30T16:04:18 | CVE Modified Date | updated | |
2022-12-30 16:17:24 | Undergoing Analysis | Analyzed | Vulnerability Status | updated |
2022-12-30 16:17:25 | Weakness Enumeration | new | ||
2022-12-30 16:17:27 | CPE Information | updated | ||
2023-01-14 05:14:19 | 2023-01-14T04:15:08 | CVE Modified Date | updated | |
2023-01-14 05:14:19 | Analyzed | Modified | Vulnerability Status | updated |
2023-01-14 05:14:21 | References | updated | ||
2023-01-18 15:15:00 | Modified | Undergoing Analysis | Vulnerability Status | updated |
2023-01-23 19:13:49 | 2023-01-23T18:55:19 | CVE Modified Date | updated | |
2023-01-23 19:13:49 | Undergoing Analysis | Analyzed | Vulnerability Status | updated |
2023-03-31 12:14:19 | 2023-03-30T23:15:06 | CVE Modified Date | updated | |
2023-03-31 12:14:19 | Analyzed | Modified | Vulnerability Status | updated |
2023-03-31 12:14:20 | References | updated | ||
2023-04-11 07:13:21 | Modified | Undergoing Analysis | Vulnerability Status | updated |