CVE-2022-30784: Input Validation
Published May 26, 2022
·Updated
A crafted NTFS image can cause heap exhaustion in ntfsgetattributevalue in NTFS-3G through 2021.8.22.
Affected Software
8 affected componentsFixes available
debian/ntfs-3g
1:2017.3.23AR.3-3+deb10u21:2017.3.23AR.3-3+deb10u31:2017.3.23AR.3-4+deb11u31:2022.10.3-1
redhat/ntfs-3g<2022.5.17
2022.5.17
tuxera NTFS-3G<=2021.8.22
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Event History
May 26, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-30784?
CVE-2022-30784 is classified as a moderate severity vulnerability due to its potential to cause heap exhaustion.
2
How do I fix CVE-2022-30784?
To fix CVE-2022-30784, upgrade to ntfs-3g version 2022.5.17 or later.
3
Which software versions are affected by CVE-2022-30784?
CVE-2022-30784 affects ntfs-3g versions up to and including 2021.8.22.
4
Is CVE-2022-30784 exploitable remotely?
CVE-2022-30784 may be exploitable by an attacker with the ability to craft malicious NTFS images.
5
What platforms are impacted by CVE-2022-30784?
CVE-2022-30784 impacts various Linux distributions including Debian and Fedora when using vulnerable versions of ntfs-3g.