CVE-2022-30787: Integer Underflow
Published May 26, 2022
·Updated
An integer underflow in fuselibreaddir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
Affected Software
7 affected componentsFixes available
debian/ntfs-3g
1:2017.3.23AR.3-3+deb10u21:2017.3.23AR.3-3+deb10u31:2017.3.23AR.3-4+deb11u31:2022.10.3-1
tuxera NTFS-3G<=2021.8.22
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Event History
May 26, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-30787?
CVE-2022-30787 has a high severity rating due to the potential for arbitrary memory read operations.
2
How do I fix CVE-2022-30787?
To fix CVE-2022-30787, update to the patched versions of ntfs-3g as specified in the security advisories.
3
What versions of ntfs-3g are affected by CVE-2022-30787?
CVE-2022-30787 affects ntfs-3g versions up to and including 2021.8.22.
4
What platforms are impacted by CVE-2022-30787?
CVE-2022-30787 impacts various platforms including Debian and Fedora running affected versions of ntfs-3g.
5
Is CVE-2022-30787 publicly disclosed?
Yes, CVE-2022-30787 has been publicly disclosed and reported in several security advisories.