PT-2023-1614 · Linux+4 · Linux Kernel+4

Palash Oswal

·

Published

2023-01-09

·

Updated

2024-04-15

·

CVE-2023-26544

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.0.8
Description The issue is related to a use-after-free in the run unpack() function in the fs/ntfs3/run.c component of the Linux kernel. This occurs due to a difference between NTFS sector size and media sector size, potentially allowing an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel versions prior to 6.0.8, update to a version that includes the fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the fs/ntfs3/run.c component until a patch is available.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1015
ALT-PU-2023-1023
ALT-PU-2023-1042
ALT-PU-2023-1044
ALT-PU-2023-7007
ALT-PU-2023-7682
ALT-PU-2024-4263
ALT-PU-2024-4843
BDU:2023-01122
CVE-2023-26544
OESA-2023-1284
USN-6079-1
USN-6091-1
USN-6096-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Ubuntu