FEDORA-2022-7fda04ab5a
Packages in this update:
cifs-utils-6.15-1.fc35
Update description:
This is a security release to address the following bugs:
CVE-2022-27239: mount.cifs: fix length check for ip option parsing
CVE-2022-29869: mount.cifs: fix verbose messages on option parsing
Description
CVE-2022-27239:
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
CVE-2022-29869:
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is
not a valid credentials file.
Both issues were originally reported and fixed by Jeffrey Bencteux.
More Stories
pgadmin4-9.2-1.fc41
FEDORA-2025-49d6f62c0e Packages in this update: pgadmin4-9.2-1.fc41 Update description: Update to pgadmin-9.2. Read More
java-latest-openjdk-24.0.1.0.9-1.rolling.el9
FEDORA-EPEL-2025-69dbee5b72 Packages in this update: java-latest-openjdk-24.0.1.0.9-1.rolling.el9 Update description: April 2025 CPU Fixed alternatives priority Java-latest-openjdk updated to jdk 24 Read...
java-latest-openjdk-24.0.1.0.9-1.rolling.el10_0 java-latest-openjdk-portable-24.0.1.0.9-1.rolling.el8
FEDORA-EPEL-2025-eb6bb14364 Packages in this update: java-latest-openjdk-24.0.1.0.9-1.rolling.el10_0 java-latest-openjdk-portable-24.0.1.0.9-1.rolling.el8 Update description: April 2025 CPU First jdk24 for epel10 Read More
java-1.8.0-openjdk-portable-1.8.0.452.b06-2.fc39 java-17-openjdk-portable-17.0.15.0.6-1.fc40
FEDORA-2025-5c15947cd4 Packages in this update: java-17-openjdk-portable-17.0.15.0.6-1.fc40 java-1.8.0-openjdk-portable-1.8.0.452.b06-2.fc39 Update description: April 2025 CPU Read More
java-1.8.0-openjdk-1.8.0.452.b06-1.fc40
FEDORA-2025-b6323169bc Packages in this update: java-1.8.0-openjdk-1.8.0.452.b06-1.fc40 Update description: April 2025 CPU Read More
java-1.8.0-openjdk-1.8.0.452.b06-1.fc41
FEDORA-2025-e81dbae527 Packages in this update: java-1.8.0-openjdk-1.8.0.452.b06-1.fc41 Update description: April 2025 CPU Read More