PT-2021-7228 · Ntfs-3G+10 · Ntfs-3G+10

Msuhanov

·

Published

2021-11-05

·

Updated

2024-06-15

·

CVE-2021-46790

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NTFS-3G versions through 2021.8.22
Description The issue is related to a heap-based buffer overflow in the NTFS-3G module, specifically involving the check file record function and the ntfsck tool. This overflow occurs in dynamic memory and can be exploited by a remote attacker to execute arbitrary code with elevated privileges using a specially crafted malicious NTFS file system. The ntfsck tool is noted to be deprecated upstream but is still shipped by some Linux distributions.
Recommendations For NTFS-3G versions through 2021.8.22, consider disabling the ntfsck tool or restricting its use until a patch is available to mitigate the risk of exploitation. As a temporary workaround, avoid using the check file record function in the NTFS-3G module until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2179
ALSA-2023:2757
ALT-PU-2022-3191
ALT-PU-2022-3208
ALT-PU-2022-3230
ALT-PU-2023-1655
ALT-PU-2023-4812
AZL-9597
BDU:2022-03917
CESA-2023_2757
CVE-2021-46790
DLA-3055-1
DSA-5160-1
MGASA-2022-0385
OESA-2022-1685
OPENSUSE-SU-2022_2835-1
OPENSUSE-SU-2024:12115-1
RHSA-2023:2179
RHSA-2023:2757
RHSA-2023_2179
RHSA-2023_2757
SUSE-SU-2022:2835-1
SUSE-SU-2022:2836-1
SUSE-SU-2022_2836-1
USN-5452-1
USN-5463-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Ntfs-3G
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu