CVE-2023-45897

NameCVE-2023-45897
Descriptionexfatprogs before 1.2.2 allows out-of-bounds memory access, such as in read_file_dentry_set.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3861-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
exfatprogs (PTS)bullseye1.1.0-1vulnerable
bullseye (security)1.1.0-1+deb11u1fixed
bookworm1.2.0-1+deb12u1fixed
sid, trixie1.2.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
exfatprogssourcebullseye1.1.0-1+deb11u1DLA-3861-1
exfatprogssourcebookworm1.2.0-1+deb12u1
exfatprogssource(unstable)1.2.2-1

Notes

https://github.com/exfatprogs/exfatprogs/commit/ec78688e5fb5a70e13df82b4c0da1e6228d3ccdf (1.2.2)
https://github.com/exfatprogs/exfatprogs/commit/22d0e43e8d24119cbfc6efafabb0dec6517a86c4 (1.2.2)
https://github.com/exfatprogs/exfatprogs/commit/4abc55e976573991e6a1117bb2b3711e59da07ae (1.2.2)

Search for package or bug name: Reporting problems