UBUNTU-CVE-2023-52631
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-52631
UBUNTU-CVE-2023-52631
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix an NULL dereference bug The issue here is when this is called from ntfs_load_attr_list(). The "size" comes from le32_to_cpu(attr->res.data_size) so it can't overflow on a 64bit systems but on 32bit systems the "+ 1023" can overflow and the result is zero. This means that the kmalloc will succeed by returning the ZERO_SIZE_PTR and then the memcpy() will crash with an Oops on the next line.
References: https://ubuntu.com/security/CVE-2023-52631, https://git.kernel.org/linus/b2dd7b953c25ffd5912dda17e980e7168bebcf6c, https://git.kernel.org/stable/c/ae4acad41b0f93f1c26cc0fc9135bb79d8282d0b, https://git.kernel.org/stable/c/ec1bedd797588fe38fc11cba26d77bb1d9b194c6, https://git.kernel.org/stable/c/fb7bcd1722bc9bc55160378f5f99c01198fd14a7, https://git.kernel.org/stable/c/686820fe141ea0220fc6fdfc7e5694f915cf64b2, https://git.kernel.org/stable/c/b2dd7b953c25ffd5912dda17e980e7168bebcf6c, https://www.cve.org/CVERecord?id=CVE-2023-52631, https://ubuntu.com/security/notices/USN-6766-1, https://ubuntu.com/security/notices/USN-6766-2, https://ubuntu.com/security/notices/USN-6766-3, https://ubuntu.com/security/notices/USN-6795-1, https://ubuntu.com/security/notices/USN-6828-1, https://ubuntu.com/security/notices/USN-6895-1, https://ubuntu.com/security/notices/USN-6895-2, https://ubuntu.com/security/notices/USN-6900-1, https://ubuntu.com/security/notices/USN-6895-3, https://ubuntu.com/security/notices/USN-6895-4
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
