openwrt ▾
›
openwrt-25.12 ▾
›
vulnerability
›
CVE-2022-29869
Component Overview
Vulnerability Overview
Name
CVE-2022-29869
Source
NVD (
link
)
Debian (
link
)
Description
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
CWEs
CWE-532
Published Date
Apr 28, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/piastry/cifs-utils/commit/8acc963a2e7e9d63fe1f2e7f73f5a03f83d9c379
Patch
https://github.com/piastry/cifs-utils/pull/7
Patch
https://lists.debian.org/debian-lts-announce/2022/05/msg00020.html
Mailing List
https://www.debian.org/security/2022/dsa-5157
Third Party Advisory
https://github.com/piastry/cifs-utils/commit/8acc963a2e7e9d63fe1f2e7f73f5a03f83d9c379
Patch
https://github.com/piastry/cifs-utils/pull/7
Patch
https://lists.debian.org/debian-lts-announce/2022/05/msg00020.html
Mailing List
https://www.debian.org/security/2022/dsa-5157
Third Party Advisory
Analysis
#
Affected Component
Analysis
cifs-utils
Exploitable
Vulnerability Ratings
#
5.3
CVSSv31
4.3
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
cifs-utils
buildroot
2025.02.x
7.4
Not Affected
cifs-utils
buildroot
master
7.4
Not Affected
cifs-utils
openwrt
master
7.5-r2
Not Affected
cifs-utils
yocto
kirkstone
6.15
Not Affected
cifs-utils
yocto
master
7.4
Not Affected
cifs-utils
yocto
scarthgap
7.0
Not Affected