Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-29869

16
FAUCET Score

CVE-2022-29869 is an information leak vulnerability affecting cifs-utils versions up to 6.14, specifically when verbose logging is enabled and a file containing an equals sign is processed but is not a valid credentials file. This medium-severity vulnerability (CVSS 5.3) has a low attack complexity and can be exploited remotely without user interaction, potentially leading to the disclosure of sensitive information. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.15CPE matchmatch criteria
cpe:2.3:a:samba:cifs-utils:*:*:*:*:*:*:*:*
34CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
35CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.87%
Probability of exploitation in next 30 days
EPSS Percentile
77.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0187 is in the 65th percentile among its peer group of 23,703 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 18733-16820Fixed in: 6.8-6
microsoftpatch availablevia msrc
Product: 18734-16823Fixed in: 6.14-2
microsoftpatch availablevia msrc
Product: cbl2 cifs-utils 6.14-2 on CBL Mariner 2.0Fixed in: 6.14-2
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 6.14-2
microsoftpatch availablevia msrc
Product: cm1 cifs-utils 6.8-6 on CBL Mariner 1.0Fixed in: 6.8-6
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 6.8-6
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 6.8-6
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 6.14-2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: cifs-utils
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: cifs-utils

Vendor Advisories (3)

microsoft2022-May/CVE-2022-29869

CVE-2022-29869

May 10, 2022
redhatCVE-2022-29869Low

cifs-utils: crafted input may cause an information leak

Apr 28, 2022
microsoft2022-Apr/CVE-2022-29869Moderate

cifs-utils through 6.14 with verbose logging can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.

Apr 12, 2022

References

github.com / piastry/cifs-utils/commit/8acc963a2e7e9d63fe1f2e7f73f5a03f83d9c379
PatchThird Party Advisory
github.com / piastry/cifs-utils/pull/7
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2022/05/msg00020.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/5WBOLMANBYJILXQKRRK7OCR774PXJAYY
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/HXKZLJYJJEC3TIBFLXUORRMZUKG5W676
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QIYZ4L6SLSYJQ446VJAO2VGAESURQNSP
security.gentoo.org / glsa/202311-05
debian.org / security/2022/dsa-5157
Third Party Advisory