REDHAT-BUG-2236130: Buffer Overflow
A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2236130?
The severity of REDHAT-BUG-2236130 is considered critical due to the potential for code execution via a buffer overflow.
How do I fix REDHAT-BUG-2236130?
To fix REDHAT-BUG-2236130, update NTFS-3G to version 2022.10.3 or later.
Who is affected by REDHAT-BUG-2236130?
Users running Tuxera NTFS-3G versions prior to 2022.10.3 with setuid root permissions are at risk of REDHAT-BUG-2236130.
Can REDHAT-BUG-2236130 be exploited remotely?
No, REDHAT-BUG-2236130 requires local access or physical proximity to exploit the vulnerability.
What software does REDHAT-BUG-2236130 pertain to?
REDHAT-BUG-2236130 pertains to Tuxera NTFS-3G software versions earlier than 2022.10.3.