UBUNTU-CVE-2022-48502
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-48502
UBUNTU-CVE-2022-48502
Summary:
Details: An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness during disk reads, leading to an out-of-bounds read in ntfs_set_ea in fs/ntfs3/xattr.c.
References: https://ubuntu.com/security/CVE-2022-48502, https://git.kernel.org/linus/0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b, https://syzkaller.appspot.com/bug?extid=8778f030156c6cd16d72, https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2, https://ubuntu.com/security/notices/USN-6260-1, https://ubuntu.com/security/notices/USN-6285-1, https://ubuntu.com/security/notices/USN-6300-1, https://ubuntu.com/security/notices/USN-6311-1, https://ubuntu.com/security/notices/USN-6332-1, https://ubuntu.com/security/notices/USN-6347-1, https://www.cve.org/CVERecord?id=CVE-2022-48502
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
