VulnerabilityModified
CVE-2022-48502
The ntfs3 subsystem does not properly check for correctness during disk reads, leading to an out-of-bounds read in ntfs_set_ea in fs/ntfs3/xattr.c.
HIGH 7.1EPSS 0.52%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness during disk reads, leading to an out-of-bounds read in ntfs_set_ea in fs/ntfs3/xattr.c.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 0.52% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- linux/linux kernel · netapp/h300s · netapp/h410c · netapp/h410s · netapp/h500s · netapp/h700s
- Source
- cve@mitre.org
References
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2Release Notes
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0e8235d28f3a0e9eda9f02ff67ee566d5f42b66bMailing List, Patch
- https://security.netapp.com/advisory/ntap-20230703-0004/Third Party Advisory, VDB Entry
- https://syzkaller.appspot.com/bug?extid=8778f030156c6cd16d72Exploit, Third Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2Release Notes
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0e8235d28f3a0e9eda9f02ff67ee566d5f42b66bMailing List, Patch
- https://security.netapp.com/advisory/ntap-20230703-0004/Third Party Advisory, VDB Entry
- https://syzkaller.appspot.com/bug?extid=8778f030156c6cd16d72Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.