Code Injection in NTFS-3G - CVE-2022-30785
Published: May 27, 2022
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to an arbitrary memory read and write operations issue when using libfuse-lite. A local administrator can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Fedora
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
Slackware Linux
Ubuntu
openSUSE Leap
openEuler
ntfs-3g-system-compression
ntfs-3g (Ubuntu package)
ntfs-3g (Debian package)
ntfs-3g
ntfs-3g-help
ntfs-3g-debugsource
ntfs-3g-devel
ntfs-3g-debuginfo
ntfs-3g_ntfsprogs-debugsource
ntfsprogs
ntfsprogs-debuginfo
libntfs-3g-devel
libntfs-3g84-debuginfo
libntfs-3g84
libntfs-3g87
libntfs-3g87-debuginfo
ntfs-3g_ntfsprogs-debuginfo
ntfsprogs-extra
ntfsprogs-extra-debuginfo
How to mitigate CVE-2022-30785
ntfs-3g-system-compression - addressed in versions 1.0-9.fc35, 1.0-9.fc36
ntfs-3g (Ubuntu package) - addressed in versions 1:2015.3.14AR.11ubuntu0.3+esm3, 1:2017.3.23AR.3-3ubuntu1.2, 1:2017.3.23AR.3-3ubuntu5.1, 1:2017.3.23-2ubuntu0.18.04.4, 1:2021.8.22-3ubuntu1.1
ntfs-3g (Debian package) - addressed in versions 1:2017.3.23AR.3-3+deb10u2, 1:2017.3.23AR.3-4+deb11u2
ntfs-3g - update to 2022.5.17-1
ntfs-3g-help - update to 2022.5.17-1
ntfs-3g-debugsource - update to 2022.5.17-1
ntfs-3g-devel - update to 2022.5.17-1
ntfs-3g-debuginfo - update to 2022.5.17-1
ntfs-3g - addressed in versions 2022.5.17-1.el7, 2022.5.17-1.fc35, 2022.5.17-1.fc36, 2022.5.17-2.el8, 2022.5.17-2.el9
ntfs-3g - addressed in versions 2022.5.17-5.12.1, 2022.5.17-150000.3.11.1
ntfs-3g-debuginfo - addressed in versions 2022.5.17-5.12.1, 2022.5.17-150000.3.11.1
ntfs-3g_ntfsprogs-debugsource - addressed in versions 2022.5.17-5.12.1, 2022.5.17-150000.3.11.1
ntfsprogs - addressed in versions 2022.5.17-5.12.1, 2022.5.17-150000.3.11.1
ntfsprogs-debuginfo - addressed in versions 2022.5.17-5.12.1, 2022.5.17-150000.3.11.1
libntfs-3g-devel - addressed in versions 2022.5.17-5.12.1, 2022.5.17-150000.3.11.1
libntfs-3g84-debuginfo - update to 2022.5.17-5.12.1
libntfs-3g84 - update to 2022.5.17-5.12.1
libntfs-3g87 - update to 2022.5.17-150000.3.11.1
libntfs-3g87-debuginfo - update to 2022.5.17-150000.3.11.1
ntfs-3g_ntfsprogs-debuginfo - update to 2022.5.17-150000.3.11.1
ntfsprogs-extra - update to 2022.5.17-150000.3.11.1
ntfsprogs-extra-debuginfo - update to 2022.5.17-150000.3.11.1
ntfs-3g - update to 2022.10.3
External References
Related Security Bulletins
- Multiple vulnerabilities in Tuxera NTFS-3G
- Ubuntu update for ntfs-3g
- Debian update for ntfs-3g
- Ubuntu update for ntfs-3g
- SUSE update for ntfs-3g_ntfsprogs
- SUSE update for ntfs-3g_ntfsprogs
- Slackware Linux update for ntfs-3g
- openEuler update for ntfs-3g
- Fedora 36 update for ntfs-3g
- Fedora 35 update for ntfs-3g
- Fedora 36 update for ntfs-3g-system-compression
- Fedora 35 update for ntfs-3g-system-compression
- Fedora EPEL 7 update for ntfs-3g
- Fedora EPEL 8 update for ntfs-3g
- Fedora EPEL 9 update for ntfs-3g