CVE-2023-52890

NameCVE-2023-52890
DescriptionNTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1073248

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ntfs-3g (PTS)bullseye (security), bullseye1:2017.3.23AR.3-4+deb11u3vulnerable
bookworm1:2022.10.3-1vulnerable
sid, trixie1:2022.10.3-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ntfs-3gsource(unstable)1:2022.10.3-31073248

Notes

[bookworm] - ntfs-3g <no-dsa> (Minor issue)
[bullseye] - ntfs-3g <no-dsa> (Minor issue)
[buster] - ntfs-3g <postponed> (Minor issue; can be fixed in next update)
https://github.com/tuxera/ntfs-3g/issues/84
Fixed by: https://github.com/tuxera/ntfs-3g/commit/75dcdc2cf37478fad6c0e3427403d198b554951d

Search for package or bug name: Reporting problems