An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write.
Loading...
Loading...
Score 8.1 from GitHub Security Advisory (severity: HIGH) published 2022-12-23. NVD baseline CVSS 8.1; sources differ by 0.0.
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write.
December 23, 2022
April 14, 2025
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | linux-image-lowlatency (5.15.0.60.53) @ jammy | 2026-05-25 | ubuntu |
| ubuntu | linux-modules-extra-5.15.0-1027-gke (5.15.0-1027.32) @ jammy | 2026-05-25 | ubuntu |
| ubuntu | linux-modules-extra-5.15.0-1027-gke (5.15.0-1027.32~20.04.1) @ focal | 2026-05-25 | ubuntu |
| ubuntu | linux-headers-azure-fde (5.15.0.1033.40.10) @ jammy | 2026-05-25 | ubuntu |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write.
Linux kernel vulnerabilities
Linux kernel (GKE) vulnerabilities
Linux kernel vulnerabilities
Linux kernel (GKE) vulnerabilities
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2022-47940
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
ubuntu · msrc
CWE-125