CVE-2022-3238
published 2022-11-14CVE-2022-3238: A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.3th percentile
A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ntfs3 local privledge escalation if NTFS character set and remount and umount called simultaneously
vendor_redhat·2022-09-22·CVSS 7.8
CVE-2022-3238 [HIGH] CWE-1341 kernel: ntfs3 local privledge escalation if NTFS character set and remount and umount called simultaneously
kernel: ntfs3 local privledge escalation if NTFS character set and remount and umount called simultaneously
A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.
A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Pa
Debian
CVE-2022-3238: linux - A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user...
vendor_debian·2022·CVSS 7.8
CVE-2022-3238 [HIGH] CVE-2022-3238: linux - A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user...
A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Scope: local
bookworm: open
bullseye: resolved
forky: open
sid: open
trixie: open
GHSA
GHSA-vrr6-jm4r-hqvp: A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously
ghsa_unreviewed·2023-07-06
CVE-2022-3238 [HIGH] CWE-415 GHSA-vrr6-jm4r-hqvp: A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously
A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.
OSV
CVE-2022-3238: A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously
osv·2022-11-14·CVSS 7.8
CVE-2022-3238 [HIGH] CVE-2022-3238: A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously
A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-14
Published