PT-2025-40193 · Ntfs3+3 · Ntfs3+3
Published
2022-10-27
·
Updated
2026-03-14
·
CVE-2023-53486
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.0.0-rc7+
Description
The Linux kernel contains an issue within the NTFS3 file system implementation. Specifically, the attribute size check has been enhanced to combine overflow and boundary checks, addressing a potential flaw in how attribute sizes are examined during enumeration. This enhancement resolves a kernel bug identified through KASAN (Kernel Address Sanitizer) testing, which detected a slab-out-of-bounds read during the
run unpack function. The issue was triggered during mount operations and involved accessing memory outside the allocated buffer. The root cause is related to improper handling of attribute sizes, potentially leading to information disclosure or system instability.Recommendations
Update to a version newer than 6.0.0-rc7+ to address this issue.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linux Kernel
Ntfs3