PT-2023-1614 · Linux+4 · Linux Kernel+4

Palash Oswal

·

Publicado

2023-01-09

·

Atualizado

2024-04-15

·

CVE-2023-26544

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.0.8
Description The issue is related to a use-after-free in the run unpack() function in the fs/ntfs3/run.c component of the Linux kernel. This occurs due to a difference between NTFS sector size and media sector size, potentially allowing an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel versions prior to 6.0.8, update to a version that includes the fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the fs/ntfs3/run.c component until a patch is available.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-1015
ALT-PU-2023-1023
ALT-PU-2023-1042
ALT-PU-2023-1044
ALT-PU-2023-7007
ALT-PU-2023-7682
ALT-PU-2024-4263
ALT-PU-2024-4843
BDU:2023-01122
CVE-2023-26544
OESA-2023-1284
USN-6079-1
USN-6091-1
USN-6096-1

Produtos afetados

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Ubuntu