HIGH
kernel: ntfs3: out-of-bounds write in mi_enum_attr()
Published Mar 19, 2023
7.8
HIGHCVSS 3.1
EPSS 0.27%
Description
In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names. An out-of-bounds write may occur.
Affected products
No data.
OR
- ≥ 5.15 · < 5.15.87
- ≥ 5.16 · < 6.0.17
- ≥ 6.1 · < 6.1.3
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux is not affected by this flaw as it does not include support for the NTFS3 file system driver.
Weaknesses (1)
References (7)
- https://access.redhat.com/security/cve/CVE-2022-48423 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2179832 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.3 Mailing ListPatchRelease NotesVendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=54e45702b648b7c0000e90b3e9b890e367e16ea8 PatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-48423
- https://security.netapp.com/advisory/ntap-20230505-0003/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-48423
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-48423 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2179832 | Issue Tracking | |
| https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.3 | Mailing ListPatchRelease NotesVendor Advisory | |
| https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=54e45702b648b7c0000e90b3e9b890e367e16ea8 | PatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-48423 | ||
| https://security.netapp.com/advisory/ntap-20230505-0003/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-48423 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 19, 2023
Updated Feb 27, 2025
Reserved Mar 19, 2023
Link CVE-2022-48423
CISA Vulnrichment
Updated Feb 27, 2025