PT-2022-6640 · Linux+5 · Linux Kernel+5

Syzbot

·

Published

2022-11-14

·

Updated

2024-04-15

·

CVE-2022-48502

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.2
Description The issue is related to the ntfs3 subsystem in the Linux kernel, which does not properly check for correctness during disk reads. This leads to an out-of-bounds read in the ntfs set ea function in fs/ntfs3/xattr.c. The vulnerability can be exploited to gain access to protected information or cause a denial of service.
Recommendations For Linux kernel versions prior to 6.2, update to version 6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the ntfs set ea function in fs/ntfs3/xattr.c to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1434
ALT-PU-2023-1539
ALT-PU-2024-4263
ALT-PU-2024-4843
AZL-27060
BDU:2023-02995
CVE-2022-48502
OESA-2023-1361
OESA-2023-1362
OESA-2023-1367
OESA-2023-1369
USN-6260-1
USN-6285-1
USN-6300-1
USN-6311-1
USN-6332-1
USN-6347-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu