PT-2025-37558 · Ntfs3+4 · Ntfs3+4

Published

2023-01-01

·

Updated

2026-04-17

·

CVE-2023-53194

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.0.0-rc7
Description A use-after-free vulnerability exists in the Linux kernel's NTFS3 filesystem, specifically within the indx get root function. The vulnerability is due to a missing length check, potentially allowing for improper index root retrieval. This can lead to a kernel crash as demonstrated by KASAN reports.
Recommendations Update to a newer version of the Linux kernel that contains a fix for this vulnerability. As a temporary workaround, consider disabling the use of the NTFS3 filesystem if possible.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-53194
OESA-2026-1950

Affected Products

Astra Linux
Debian
Linux Kernel
Ntfs3
Red Os