CVE-2023-52890

NameCVE-2023-52890
DescriptionNTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesELA-1197-1
Debian Bugs1073248

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ntfs-3g (PTS)jessie, jessie (lts)1:2014.2.15AR.2-1+deb8u7vulnerable
stretch (security)1:2016.2.22AR.1+dfsg-1+deb9u3vulnerable
stretch (lts), stretch1:2016.2.22AR.1+dfsg-1+deb9u5fixed
buster, buster (lts)1:2017.3.23AR.3-4+deb11u4~deb10u1fixed
buster (security)1:2017.3.23AR.3-3+deb10u3vulnerable
bullseye1:2017.3.23AR.3-4+deb11u4fixed
bullseye (security)1:2017.3.23AR.3-4+deb11u3vulnerable
bookworm1:2022.10.3-1+deb12u2fixed
sid, trixie1:2022.10.3-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ntfs-3gsourcestretch1:2016.2.22AR.1+dfsg-1+deb9u5ELA-1197-1
ntfs-3gsourcebuster1:2017.3.23AR.3-4+deb11u4~deb10u1ELA-1197-1
ntfs-3gsourcebullseye1:2017.3.23AR.3-4+deb11u4
ntfs-3gsourcebookworm1:2022.10.3-1+deb12u1
ntfs-3gsource(unstable)1:2022.10.3-31073248

Notes

[buster] - ntfs-3g <postponed> (Minor issue; can be fixed in next update)
https://github.com/tuxera/ntfs-3g/issues/84
Fixed by: https://github.com/tuxera/ntfs-3g/commit/75dcdc2cf37478fad6c0e3427403d198b554951d
[jessie] - ntfs-3g <postponed> (Minor issue; can be fixed in next update)

Search for package or bug name: Reporting problems