CVE-2022-30786 is a heap-based buffer overflow vulnerability in NTFS-3G, affecting versions through 2021.8.22, including various Debian and Fedora distributions. This flaw can be triggered by processing a specially crafted NTFS image. With a CVSS score of 7.8 (High), it poses a significant risk, allowing for potential confidentiality, integrity, and availability impacts with low attack complexity and user interaction. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2021.8.22CPE matchmatch criteria | cpe:2.3:a:tuxera:ntfs-3g:*:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-30786
Jun 14, 2022ntfs-3g: crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate
May 26, 2022A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.
May 10, 2022