Описание
A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_attr_record_resize, in NTFS-3G < 2021.8.22.
The ntfs3g package is susceptible to an input validation flaw. A crafted NTFS image with invalid values could trigger an improper check. This incorrect check causes an integer overflow which then leads to a heap overflow. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | libguestfs-winsupport | Out of support scope | ||
Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.2/libguestfs-winsupport | Affected | ||
Red Hat Enterprise Linux 8 Advanced Virtualization | virt:av/libguestfs-winsupport | Affected | ||
Red Hat Enterprise Linux 9 | libguestfs-winsupport | Affected | ||
Advanced Virtualization for RHEL 8.2.1 | virt | Fixed | RHSA-2021:3704 | 30.09.2021 |
Advanced Virtualization for RHEL 8.2.1 | virt-devel | Fixed | RHSA-2021:3704 | 30.09.2021 |
Advanced Virtualization for RHEL 8.4.0.Z | virt | Fixed | RHSA-2021:3703 | 30.09.2021 |
Advanced Virtualization for RHEL 8.4.0.Z | virt-devel | Fixed | RHSA-2021:3703 | 30.09.2021 |
Red Hat Enterprise Linux 8 | virt-devel | Fixed | RHSA-2022:1759 | 10.05.2022 |
Red Hat Enterprise Linux 8 | virt | Fixed | RHSA-2022:1759 | 10.05.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_attr_record_resize, in NTFS-3G < 2021.8.22.
A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_attr_record_resize, in NTFS-3G < 2021.8.22.
A crafted NTFS image can cause an integer overflow in memmove, leading ...
A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_attr_record_resize, in NTFS-3G < 2021.8.22.
EPSS
7.8 High
CVSS3