PT-2022-3223 · Ntfs-3G+7 · Ntfs-3G+7

Roman Fiedler

·

Published

2022-05-16

·

Updated

2024-04-03

·

CVE-2022-30787

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NTFS-3G versions through 2021.8.22 when using libfuse-lite
Description The issue is related to an integer underflow in the fuse lib readdir function of the libfuse-lite library for the NTFS file system in the FUSE NTFS-3G module. This can enable arbitrary memory read operations. Exploitation of the issue may allow an attacker to execute arbitrary code with elevated privileges using a specially crafted request.
Recommendations For NTFS-3G versions through 2021.8.22 when using libfuse-lite, consider disabling the fuse lib readdir function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Integer Underflow

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3191
ALT-PU-2022-3208
ALT-PU-2022-3230
ALT-PU-2023-1655
ALT-PU-2023-4812
AZL-9859
BDU:2022-03924
CVE-2022-30787
DLA-3055-1
DSA-5160-1
GHSA-6MV4-4V73-XW58
MGASA-2022-0385
OESA-2022-1685
OPENSUSE-SU-2022_2835-1
SUSE-SU-2022:2835-1
SUSE-SU-2022:2836-1
USN-5463-1
USN-5463-2

Affected Products

Alt Linux
Astra Linux
Linuxmint
Ntfs-3G
Red Os
Suse
Ubuntu
Libfuse-Lite