In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names. An out-of-bounds write may occur.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=54e45702b648b7c0000e90b3e9b890e367e16ea8 | patch vendor advisory |
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.3 | mailing list release notes patch vendor advisory |
https://security.netapp.com/advisory/ntap-20230505-0003/ | third party advisory |