SUSE-SU-2022:2835-1

Advisory lineage Upstream: 8 Downstream: 0
Published: 17 Aug 2022, 14:52
Last modified:02 May 2025, 04:32

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Aug 2022, 14:52
Published
Vulnerability first disclosed
02 May 2025, 04:32
Last Modified
Vulnerability information updated

Description

Security update for ntfs-3g_ntfsprogs This update for ntfs-3g_ntfsprogs fixes the following issues: Updated to version 2022.5.17 (bsc#1199978): - CVE-2022-30783: Fixed an issue where messages between NTFS-3G and the kernel could be intercepted when using libfuse-lite. - CVE-2022-30784: Fixed a memory exhaustion issue when opening a crafted NTFS image. - CVE-2022-30785: Fixed a bug where arbitrary memory read and write operations could be achieved whe using libfuse-lite. - CVE-2022-30786: Fixed a memory corruption issue when opening a crafted NTFS image. - CVE-2022-30787: Fixed an integer underflow which enabled arbitrary memory read operations when using libfuse-lite. - CVE-2022-30788: Fixed a memory corruption issue when opening a crafted NTFS image. - CVE-2022-30789: Fixed a memory corruption issue when opening a crafted NTFS image.

Affected Systems

  • opensusentfs-3g_ntfsprogs&distro=openSUSE Leap 15.3

    < 2022.5.17-150000.3.11.1

  • opensusentfs-3g_ntfsprogs&distro=openSUSE Leap 15.4

    < 2022.5.17-150000.3.11.1

  • susentfs-3g_ntfsprogs&distro=SUSE Linux Enterprise Workstation Extension 15 SP3

    < 2022.5.17-150000.3.11.1

  • susentfs-3g_ntfsprogs&distro=SUSE Linux Enterprise Workstation Extension 15 SP4

    < 2022.5.17-150000.3.11.1

References (10)