Related Vulnerabilities: CVE-2022-30785  

A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

Description

The MITRE CVE dictionary describes this issue as:

A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

Additional Information

  • Bugzilla 2093320: CVE-2022-30785 ntfs-3g: a file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations
  • (CWE-125|CWE-787): Out-of-bounds Read or Out-of-bounds Write
  • FAQ: Frequently asked questions about CVE-2022-30785