CVE-2022-30783

An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
VendorProductVersion
tuxerantfs-3g
𝑥
≤ 2021.8.22
debiandebian_linux
9.0
debiandebian_linux
10.0
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ntfs-3g
bullseye
1:2017.3.23AR.3-4+deb11u4
fixed
bullseye (security)
1:2017.3.23AR.3-4+deb11u3
fixed
bookworm
1:2022.10.3-1
fixed
sid
1:2022.10.3-5
fixed
trixie
1:2022.10.3-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ntfs-3g
kinetic
Fixed 2022.5.17-1ubuntu1
released
jammy
Fixed 1:2021.8.22-3ubuntu1.1
released
impish
Fixed 1:2017.3.23AR.3-3ubuntu5.1
released
focal
Fixed 1:2017.3.23AR.3-3ubuntu1.2
released
bionic
Fixed 1:2017.3.23-2ubuntu0.18.04.4
released
xenial
Fixed 1:2015.3.14AR.1-1ubuntu0.3+esm3
released
trusty
Fixed 1:2013.1.13AR.1-2ubuntu2+esm3
released
References