PT-2025-40193 · Ntfs3+3 · Ntfs3+3

Published

2022-10-27

·

Updated

2026-03-14

·

CVE-2023-53486

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.0.0-rc7+
Description The Linux kernel contains an issue within the NTFS3 file system implementation. Specifically, the attribute size check has been enhanced to combine overflow and boundary checks, addressing a potential flaw in how attribute sizes are examined during enumeration. This enhancement resolves a kernel bug identified through KASAN (Kernel Address Sanitizer) testing, which detected a slab-out-of-bounds read during the run unpack function. The issue was triggered during mount operations and involved accessing memory outside the allocated buffer. The root cause is related to improper handling of attribute sizes, potentially leading to information disclosure or system instability.
Recommendations Update to a version newer than 6.0.0-rc7+ to address this issue.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16315
CVE-2023-53486

Affected Products

Astra Linux
Debian
Linux Kernel
Ntfs3