CVE-2021-46790

ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
Affected Products (NVD)
VendorProductVersion
tuxerantfs-3g
𝑥
≤ 2021.8.22
debiandebian_linux
10.0
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ntfs-3g
bookworm
1:2022.10.3-1
fixed
bullseye
1:2017.3.23AR.3-4+deb11u4
fixed
bullseye (security)
1:2017.3.23AR.3-4+deb11u3
fixed
sid
1:2022.10.3-5
fixed
trixie
1:2022.10.3-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ntfs-3g
bionic
Fixed 1:2017.3.23-2ubuntu0.18.04.4
released
focal
Fixed 1:2017.3.23AR.3-3ubuntu1.2
released
impish
Fixed 1:2017.3.23AR.3-3ubuntu5.1
released
jammy
Fixed 1:2021.8.22-3ubuntu1.1
released
trusty
Fixed 1:2013.1.13AR.1-2ubuntu2+esm2
released
xenial
Fixed 1:2015.3.14AR.1-1ubuntu0.3+esm2
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libntfs-3g-devel
suse enterprise desktop 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP5
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP5
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP5
2022.5.17-150000.3.11.1
fixed
suse enterprise workstation 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise workstation 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise workstation 15 SP5
2022.5.17-150000.3.11.1
fixed
libntfs-3g87
suse enterprise desktop 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP5
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP6
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP7
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP5
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP6
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP7
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP5
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP6
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP7
2022.5.17-150000.3.11.1
fixed
suse enterprise workstation 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise workstation 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise workstation 15 SP5
2022.5.17-150000.3.11.1
fixed
ntfs-3g
suse enterprise desktop 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP5
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP6
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP7
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP5
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP6
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP7
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP5
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP6
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP7
2022.5.17-150000.3.11.1
fixed
suse enterprise workstation 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise workstation 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise workstation 15 SP5
2022.5.17-150000.3.11.1
fixed
ntfsprogs
suse enterprise desktop 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP5
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP6
2022.5.17-150000.3.11.1
fixed
suse enterprise desktop 15 SP7
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP5
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP6
2022.5.17-150000.3.11.1
fixed
suse enterprise sap 15 SP7
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP5
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP6
2022.5.17-150000.3.11.1
fixed
suse enterprise server 15 SP7
2022.5.17-150000.3.11.1
fixed
suse enterprise workstation 15 SP3
2022.5.17-150000.3.11.1
fixed
suse enterprise workstation 15 SP4
2022.5.17-150000.3.11.1
fixed
suse enterprise workstation 15 SP5
2022.5.17-150000.3.11.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libguestfs-winsupport
RHEL 9
0:9.2-1.el9
fixed