UBUNTU-CVE-2023-53732
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-53732
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix NULL dereference in ni_write_inode Syzbot reports a NULL dereference in ni_write_inode. When creating a new inode, if allocation fails in mi_init function (called in mi_format_new function), mi->mrec is set to NULL. In the error path of this inode creation, mi->mrec is later dereferenced in ni_write_inode. Add a NULL check to prevent NULL dereference.
References: https://ubuntu.com/security/CVE-2023-53732, https://www.cve.org/CVERecord?id=CVE-2023-53732, https://git.kernel.org/linus/8dae4f6341e335a09575be60b4fdf697c732a470, https://git.kernel.org/stable/c/8dae4f6341e335a09575be60b4fdf697c732a470, https://git.kernel.org/stable/c/b1135fbaf8ebef93df326761ac70ebcc3c2e3d63, https://git.kernel.org/stable/c/b3152afc0eb864f7c6ecad134a15b577ef7aec77, https://git.kernel.org/stable/c/d4b74482529516477cf7b12502538e51827c699f
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
