EN

Tracker / CVE-2023-52631

CVE-2023-52631

Media 5.5

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix an NULL dereference bug The issue here is when this is called from ntfs_load_attr_list(). The "size" comes from le32_to_cpu(attr->res.data_size) so it can't overflow on a 64bit systems but on 32bit systems the "+ 1023" can overflow and the result is zero. This means that the kmalloc will succeed by returning the ZERO_SIZE_PTR and then the memcpy() will crash with an Oops on the next line.

Prodotti e versioni affette

linux linux_kernel
linux linux_kernel · 5.15 → 5.15.149
linux linux_kernel · 5.16 → 6.1.78
linux linux_kernel · 6.2 → 6.6.17
linux linux_kernel · 6.7 → 6.7.5

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti