PT-2025-37558 · Ntfs3+4 · Ntfs3+4
Published
2023-01-01
·
Updated
2026-04-17
·
CVE-2023-53194
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.0.0-rc7
Description
A use-after-free vulnerability exists in the Linux kernel's NTFS3 filesystem, specifically within the
indx get root function. The vulnerability is due to a missing length check, potentially allowing for improper index root retrieval. This can lead to a kernel crash as demonstrated by KASAN reports.Recommendations
Update to a newer version of the Linux kernel that contains a fix for this vulnerability. As a temporary workaround, consider disabling the use of the NTFS3 filesystem if possible.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linux Kernel
Ntfs3
Red Os