Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-50247

Опубликовано: 09 нояб. 2024
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Check if more than chunk-size bytes are written A incorrectly formatted chunk may decompress into more than LZNT_CHUNK_SIZE bytes and a index out of bounds will occur in s_max_off.

A flaw was found in the Linux kernel's NTFS3 file system driver. An attacker with local access could craft a specially malformed NTFS compressed chunk. When this chunk is decompressed, it can lead to an out-of-bounds write, potentially causing a denial of service or other system instability.

Меры по смягчению последствий

To prevent the ntfs3 kernel module from loading, blacklist it. This action may affect systems requiring the mounting of NTFS filesystems.

  1. Create /etc/modprobe.d/blacklist-ntfs3.conf with blacklist ntfs3.
  2. Regenerate the initramfs: dracut -f -v (RHEL 8/9) or mkinitrd -f -v /boot/initramfs-$(uname -r).img $(uname -r) (RHEL 7).
  3. Reboot the system to ensure the module is not loaded. If the module is currently loaded, it can be unloaded with rmmod ntfs3, but a reboot is necessary for persistent blacklisting.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2324888kernel: fs/ntfs3: Check if more than chunk-size bytes are written

EPSS

Процентиль: 14%
0.00228
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Check if more than chunk-size bytes are written A incorrectly formatted chunk may decompress into more than LZNT_CHUNK_SIZE bytes and a index out of bounds will occur in s_max_off.

CVSS3: 7.3
nvd
почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Check if more than chunk-size bytes are written A incorrectly formatted chunk may decompress into more than LZNT_CHUNK_SIZE bytes and a index out of bounds will occur in s_max_off.

CVSS3: 7.1
msrc
7 месяцев назад

fs/ntfs3: Check if more than chunk-size bytes are written

CVSS3: 7.3
debian
почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: f ...

CVSS3: 7.1
github
почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Check if more than chunk-size bytes are written A incorrectly formatted chunk may decompress into more than LZNT_CHUNK_SIZE bytes and a index out of bounds will occur in s_max_off.

EPSS

Процентиль: 14%
0.00228
Низкий

7.1 High

CVSS3

Уязвимость CVE-2024-50247