cbcvebase.
CVE-2023-26607
published 2023-02-26

CVE-2023-26607: In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c.

high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.19.37-1 (bookworm)linux 4.19.37-1 (bookworm)
linuxlinux_kernel>= 0 < 4.19.37-14.19.37-1
linuxlinux_kernel>= 0 < 4.19.37-14.19.37-1
linuxlinux_kernel>= 0 < 4.19.37-14.19.37-1
linuxlinux_kernel>= 0 < 4.19.37-14.19.37-1
linuxlinux_kernel>= 0 < 4.4.0-239.2734.4.0-239.273
linuxlinux_kernel>= 2.6.12 < 4.9.3344.9.334
linuxlinux_kernel>= 4.10 < 4.14.3004.14.300
linuxlinux_kernel>= 4.15 < 4.19.2674.19.267
linuxlinux_kernel>= 4.20 < 5.4.2255.4.225
linuxlinux_kernel>= 5.11 < 5.15.805.15.80
linuxlinux_kernel>= 5.16 < 6.0.106.0.10
linuxlinux_kernel>= 5.5.0 < 5.10.1565.10.156
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH