PT-2022-3033 · Ntfs-3G+10 · Ntfs-3G+10

Published

2022-05-16

·

Updated

2024-06-15

·

CVE-2022-30788

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NTFS-3G versions through 2021.8.22
Description A crafted NTFS image can cause a heap-based buffer overflow in the ntfs mft rec alloc function of the NTFS-3G file system, potentially allowing an attacker to execute arbitrary code with elevated privileges. This issue is related to a buffer overflow in dynamic memory.
Recommendations For NTFS-3G versions through 2021.8.22, consider disabling the ntfs mft rec alloc function as a temporary workaround until a patch is available. Restrict access to specially crafted NTFS images to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

RCE

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2179
ALSA-2023:2757
ALT-PU-2022-3191
ALT-PU-2022-3208
ALT-PU-2022-3230
ALT-PU-2023-1655
ALT-PU-2023-4812
AZL-9850
BDU:2022-03701
CESA-2023_2757
CVE-2022-30788
DLA-3055-1
DSA-5160-1
GHSA-XCHM-PH5H-HW4X
MGASA-2022-0385
OESA-2022-1685
OPENSUSE-SU-2022_2835-1
OPENSUSE-SU-2024:12115-1
RHSA-2023:2179
RHSA-2023:2757
RHSA-2023_2179
RHSA-2023_2757
SUSE-SU-2022:2835-1
SUSE-SU-2022:2836-1
USN-5463-1
USN-5463-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Ntfs-3G
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu