Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
ntfs3: fix integer overflow in run_unpack() volume boundary check
The volume boundary check lcn + len > sbi->used.bitmap.nbits uses raw
addition which can wrap around for large lcn and len values, bypassing
the validation. Use check_add_overflow() as is already done for the
adjacent prev_lcn + dlcn and vcn64 + len checks added by commit
3ac37e100385 (“ntfs3: Fix integer overflow in run_unpack()”).
Found by fuzzing with a source-patched harness (LibAFL + QEMU).
Details
- Affected product:
- Ubuntu 20.04 ELS
- Affected packages:
- linux-meta @ 5.4.0 (+1 more)
Fixes
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| Amazon Linux 2023 | Released |
57 kernels
|
| Debian 12 | Planned | — |
| Debian 13 | Released |
6 kernels
|
| Proxmox VE 7 5.15 | Released |
47 kernels
|
| Ubuntu 20.04 HWE AWS | Released |
57 kernels
|
| Ubuntu 20.04 HWE Azure | Released |
40 kernels
|
| Ubuntu 22.04 | Released |
97 kernels
|
| Ubuntu 22.04 AWS | Released |
88 kernels
|
| Ubuntu 22.04 Azure | Released |
78 kernels
|
| Ubuntu 24.04 | Released |
46 kernels
|