Описание
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
The ntfs3g package is susceptible to a heap overflow on crafted input. When processing NTFS inodes, proper bounds checking was not enforced leading to this software flaw. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | libguestfs-winsupport | Out of support scope | ||
Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.2/libguestfs-winsupport | Affected | ||
Red Hat Enterprise Linux 8 Advanced Virtualization | virt:av/libguestfs-winsupport | Affected | ||
Red Hat Enterprise Linux 9 | libguestfs-winsupport | Affected | ||
Advanced Virtualization for RHEL 8.2.1 | virt | Fixed | RHSA-2021:3704 | 30.09.2021 |
Advanced Virtualization for RHEL 8.2.1 | virt-devel | Fixed | RHSA-2021:3704 | 30.09.2021 |
Advanced Virtualization for RHEL 8.4.0.Z | virt | Fixed | RHSA-2021:3703 | 30.09.2021 |
Advanced Virtualization for RHEL 8.4.0.Z | virt-devel | Fixed | RHSA-2021:3703 | 30.09.2021 |
Red Hat Enterprise Linux 8 | virt-devel | Fixed | RHSA-2022:1759 | 10.05.2022 |
Red Hat Enterprise Linux 8 | virt | Fixed | RHSA-2022:1759 | 10.05.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode i ...
Tuxera NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
EPSS
7.8 High
CVSS3