PT-2022-3038 · Ntfs-3G+10 · Ntfs-3G+10

Published

2022-05-26

·

Updated

2024-04-03

·

CVE-2022-30789

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NTFS-3G versions through 2021.8.22
Description A crafted NTFS image can cause a heap-based buffer overflow in the ntfs check log client array function. This issue is related to the NTFS file system for the FUSE NTFS-3G module and is associated with a buffer overflow in dynamic memory. Exploitation of this issue may allow an attacker to execute arbitrary code with elevated privileges using a specially crafted NTFS image file.
Recommendations For NTFS-3G versions through 2021.8.22, consider disabling the ntfs check log client array function as a temporary workaround until a patch is available. Restrict access to NTFS image files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

DoS

Memory Corruption

RCE

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2023:2179
ALSA-2023:2757
ALT-PU-2022-3191
ALT-PU-2022-3208
ALT-PU-2022-3230
ALT-PU-2023-1655
ALT-PU-2023-4812
AZL-9851
BDU:2022-03707
CESA-2023_2757
CVE-2022-30789
DLA-3055-1
DSA-5160-1
GHSA-XCHM-PH5H-HW4X
MGASA-2022-0385
OESA-2022-1685
OPENSUSE-SU-2022_2835-1
RHSA-2023:2179
RHSA-2023:2757
RHSA-2023_2179
RHSA-2023_2757
SUSE-SU-2022:2835-1
SUSE-SU-2022:2836-1
USN-5463-1
USN-5463-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Ntfs-3G
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu