cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
[
{
"id": "CVE-2022-29869-079112c6",
"source": "https://github.com/piastry/cifs-utils/commit/8acc963a2e7e9d63fe1f2e7f73f5a03f83d9c379",
"signature_version": "v1",
"digest": {
"length": 1476.0,
"function_hash": "91061460177468123754902069861250535461"
},
"target": {
"function": "open_cred_file",
"file": "mount.cifs.c"
},
"signature_type": "Function",
"deprecated": false
},
{
"id": "CVE-2022-29869-308c8667",
"source": "https://github.com/piastry/cifs-utils/commit/8acc963a2e7e9d63fe1f2e7f73f5a03f83d9c379",
"signature_version": "v1",
"digest": {
"line_hashes": [
"333177565664066831031052731575158110766",
"269008431299318842638218154133802989812",
"200416903659751381251677829170609985397",
"142948789842139240547537937641208830596",
"44912368005009940171336540415324128652",
"157149416689637315031584410539095472663",
"83440183529970733472400725653080485434",
"172559212895684826899817295477533425772",
"151755585470736387165767965852064864571",
"318376024910814506234711884201024569379",
"1076006348340887466461663850527154898",
"247924530577808540089783321436504017021",
"345905160297107181876084015619107312",
"94278264940853492957148186831503439599"
],
"threshold": 0.9
},
"target": {
"file": "mount.cifs.c"
},
"signature_type": "Line",
"deprecated": false
}
]