CVE-2022-30783: Medium severity ntfs-3g vulnerability
Published May 26, 2022
·Updated
An invalid return code in fusekernmount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite.
Affected Software
7 affected componentsFixes available
debian/ntfs-3g
1:2017.3.23AR.3-3+deb10u21:2017.3.23AR.3-3+deb10u31:2017.3.23AR.3-4+deb11u31:2022.10.3-1
tuxera NTFS-3G<=2021.8.22
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Event History
May 26, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-30783?
CVE-2022-30783 is a vulnerability in which an invalid return code in fuse_kern_mount allows intercepting libfuse-lite protocol traffic between NTFS-3G and the kernel.
2
How does CVE-2022-30783 affect NTFS-3G and the kernel?
CVE-2022-30783 affects NTFS-3G through version 2021.8.22 when using libfuse-lite, enabling interception of protocol traffic.
3
What is the severity of CVE-2022-30783?
The severity of CVE-2022-30783 is rated as medium with a CVSS score of 6.7.
4
How can I mitigate the vulnerability CVE-2022-30783?
To mitigate CVE-2022-30783, it is recommended to apply the patches provided by the software vendor.