PT-2022-3219 · Ntfs-3G+7 · Ntfs-3G+7

Roman Fiedler

·

Published

2022-05-16

·

Updated

2024-06-15

·

CVE-2022-30783

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NTFS-3G versions through 2021.8.22
Description The issue is related to an invalid return code in the fuse kern mount function of the libfuse-lite library for the NTFS-3G file system, which enables the interception of libfuse-lite protocol traffic between NTFS-3G and the kernel. Exploitation of this issue may allow an attacker to execute arbitrary code with elevated privileges using a specially crafted request.
Recommendations For NTFS-3G versions through 2021.8.22, consider disabling the fuse kern mount function as a temporary workaround until a patch is available. Restrict access to the libfuse-lite protocol to minimize the risk of exploitation. Avoid using the vulnerable function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unchecked Return Value

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3191
ALT-PU-2022-3208
ALT-PU-2022-3230
ALT-PU-2023-1655
ALT-PU-2023-4812
AZL-9846
BDU:2022-03919
CVE-2022-30783
DLA-3055-1
DSA-5160-1
GHSA-6MV4-4V73-XW58
MGASA-2022-0385
OESA-2022-1685
OPENSUSE-SU-2022_2835-1
OPENSUSE-SU-2024:12115-1
SUSE-SU-2022:2835-1
SUSE-SU-2022:2836-1
USN-5463-1
USN-5463-2

Affected Products

Alt Linux
Astra Linux
Linuxmint
Ntfs-3G
Red Os
Suse
Ubuntu
Libfuse-Lite