An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness during disk reads, leading to an out-of-bounds read in ntfssetea in fs/ntfs3/xattr.c.
[
{
"deprecated": false,
"target": {
"function": "indx_read",
"file": "fs/ntfs3/index.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"function_hash": "70835537886014984379264790500597225966",
"length": 1559.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-48502-024cb1f0"
},
{
"deprecated": false,
"target": {
"function": "indx_insert_into_root",
"file": "fs/ntfs3/index.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"function_hash": "239474970496839029955409385533599544422",
"length": 3390.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-48502-0439173a"
},
{
"deprecated": false,
"target": {
"file": "fs/ntfs3/xattr.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"line_hashes": [
"27502254882281888229589832712599820365",
"201243387275077184110236693036897112568",
"26323433339819427362019742458059881637",
"303384492210773341559382630850552596981",
"197845406508709099396805420427336745019",
"9055038263387918769773889976276525608",
"273268792879496164134628890820446972501",
"38572194765412072481782336015976195695",
"301115144079884756185192163723265124245",
"230037917361649743263354654878813438906",
"50749619726867653968272119176105299304",
"323875293932653153202990337699829494241",
"83964997190868484351568929144735041616",
"56126067306364164450433063249604306191",
"237289390790994166258024599762393212813",
"87952997934129089373249911274666647056",
"299637496058519243731943074420559859831",
"220031526530415833032131922838128924416",
"186993850162912344115227027766434299248",
"219486712328954456308002634361169452997",
"163203206158124678557014213746810372598",
"106109899226483169632523595961220756389",
"258977645021570123990052438231563269832",
"102385772650842205378340154258365516933",
"80962658926369551578973347247634070525",
"11685596656781360347861542173075970763",
"258533888962932475288468752889890710206",
"193147402099738771611484657113966871509",
"98797364219397911760061762273911622113",
"57250642115623645199481637742769382080",
"73587404507792068389627653178373229272",
"284268930528050846096353751212480649117",
"3975948696688941211960491635045557251",
"110146862274768723114189740949204462211",
"65706615888006585100211652414820384150",
"126929920223188727641585474109063371576",
"203473323002112095368968627882099559427",
"146172597687759755916655560251615948927",
"158620840445406077605583189214827534801",
"319234963723481803519399786142900849064",
"68951334012391606256262240263788898779",
"129228701353628811064466305627185000891",
"160399261880348314761732966889796448412",
"289633673725671956625146082870720708519",
"180443068421176342195251678171765012641",
"322161356817563154577168371608559968575",
"231894834263047871067568630127625487772",
"285598273167388884106881418835049859385",
"269622195869561242009469595814921252764",
"230868280182546237234777081381725514360",
"114721338807525914713400606772881049238",
"85876455436656560942359490497154411927",
"323496184096396929608494851605243878096",
"290841432478616932423753993025439072242",
"177144896023794625332239426161689223626",
"292686966559109293716302930574118814499",
"239806468174575730955428147735135860524",
"330200445748769983691248216839304522662",
"202713448475859586474073966456398494350",
"268190356690572761030000619114748541573",
"111119604881695027488359913633156524610",
"199027202949015054703050748683119793399",
"185503385390508210331217044258936993679",
"138739976925604718859261488429711269390",
"175347243425613069680408539426308062777",
"83658236283702249441650669949149410814",
"294726654441216442325278486569063337211",
"9371918172918950655066203506096471716",
"139944597872368987312844526193687744183",
"80165700238101639244101125847819254880",
"132020757620891110993787663497405066498",
"177331905857335794291335850099822541540",
"20307712605838226469927843761010180731",
"315176451537842926146287232824013512828",
"169575434524929389162495325343240298811",
"288962133580819099595260791963849199479",
"28472240253180943743675015698764398231",
"297850544577219022231800048626235114681",
"69058453734411560265809605561683498938",
"263692238593782510442881988189903704823",
"50984627094291624579987317747221833258",
"96555673592969027308550055240912245444",
"123587351950829512732340144661802375995",
"167218500916339798236011628815412239121",
"83472561026523315371586764935899024029",
"112481922633373712410520258160883455436",
"257148567412119584194751443755476670431",
"142132435074814225953872457820047058607"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2022-48502-0696e2a0"
},
{
"deprecated": false,
"target": {
"function": "ntfs_get_ea",
"file": "fs/ntfs3/xattr.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"function_hash": "170510469126422885465274785759208462698",
"length": 957.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-48502-2bf73aab"
},
{
"deprecated": false,
"target": {
"function": "ntfs_read_ea",
"file": "fs/ntfs3/xattr.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"function_hash": "40751137451316406270569099330474420795",
"length": 1340.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-48502-30d7fd06"
},
{
"deprecated": false,
"target": {
"function": "ntfs_set_ea",
"file": "fs/ntfs3/xattr.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"function_hash": "230583032408019936621701838481142519001",
"length": 3796.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-48502-319f0322"
},
{
"deprecated": false,
"target": {
"function": "ntfs_read_mft",
"file": "fs/ntfs3/inode.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"function_hash": "99213963111123039436231896855244813162",
"length": 9576.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-48502-522cffd7"
},
{
"deprecated": false,
"target": {
"function": "run_unpack",
"file": "fs/ntfs3/run.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"function_hash": "86522439799040309486983295069672980385",
"length": 1863.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-48502-574d54c8"
},
{
"deprecated": false,
"target": {
"function": "fnd_clear",
"file": "fs/ntfs3/index.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"function_hash": "98587331551292012495926841341144215026",
"length": 261.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-48502-5a74a58c"
},
{
"deprecated": false,
"target": {
"file": "fs/ntfs3/inode.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"line_hashes": [
"20861632981996434361271218076174450782",
"264653785980239598709728875743216967115",
"105634729626928030707081452436255814492",
"89114235084196801277862271173201856429",
"231541619503375487176515644532496541246",
"150597171681665074736745119722172719166",
"150826228041243395099372553288173625976",
"329463510500606687323909274082717793196",
"309338002989364135033340219733137936101",
"248406415667986419800443115130581725800",
"102147434157464753060389287450551207911",
"116211770662366406444189739293929062231",
"260137960962236905202945014864567155777",
"164385761860378002753882949030484642567",
"326115154491990637218735572511423590380",
"275076658026052474834989116674315320714",
"42788161343820856227043910846912294439",
"333481108856523896836276698720429344090",
"309022018323811221714343049991758124559",
"178079341097895896504333627362063700195",
"74479102818297354737544373501850467521",
"71202838808564933646708801471023148948"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2022-48502-7c0d91d7"
},
{
"deprecated": false,
"target": {
"function": "find_ea",
"file": "fs/ntfs3/xattr.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"function_hash": "180111129936959393869148291514653881418",
"length": 460.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-48502-7e2fa8fc"
},
{
"deprecated": false,
"target": {
"function": "indx_init",
"file": "fs/ntfs3/index.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"function_hash": "297678362601119008248910318916563988138",
"length": 863.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-48502-82ab4624"
},
{
"deprecated": false,
"target": {
"file": "fs/ntfs3/ntfs_fs.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"line_hashes": [
"126207469931638234768839846215685529950",
"76134807734573435500104871145817933099",
"277367866751035836812971084463956065853",
"7695785989112399321473522795937133904",
"266499453859274336287840359875089818483",
"175792797570426368666896269356359715378",
"298479548189307763469157006485523153052",
"123041904776533054180064404983188859476"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2022-48502-a7b5319a"
},
{
"deprecated": false,
"target": {
"file": "fs/ntfs3/run.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"line_hashes": [
"71559383141989485579488251568486770653",
"313185117798858710861221940824308786486",
"136687595435755214820162546938714538596",
"80161252742735557789693558421583264123",
"63999438770527722407216952454073392482",
"8470693961339084329126271571752024785",
"212041078815584132226704873630485705506",
"309957526767733891579375492789643401303",
"214967415767197493057310816490142274720",
"224765130661442568310711723323325141384",
"274831017889814580148742286887602968274",
"97023991585873449026142337607335364233"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2022-48502-a9eb856c"
},
{
"deprecated": false,
"target": {
"function": "ntfs_iget5",
"file": "fs/ntfs3/inode.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"function_hash": "61867503725291374142228706352691668094",
"length": 428.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-48502-ac05f783"
},
{
"deprecated": false,
"target": {
"function": "ntfs_list_ea",
"file": "fs/ntfs3/xattr.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"function_hash": "63026394008101158141136869658855859573",
"length": 677.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-48502-c1e6eba2"
},
{
"deprecated": false,
"target": {
"file": "fs/ntfs3/index.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"line_hashes": [
"133060681673177029480363750175879624345",
"89893018745354823274026836150651931530",
"145270203933472511843430419469492944512",
"104731131554107025725434225117477020512",
"109994460830793340521834418484697045842",
"206455724222062358386368570989026894102",
"70706069897251824455089225035246966999",
"113102556091869480764873801375578322005",
"254481434443325293328657651406080006875",
"85595258379230896089436073454981636428",
"328586543647957944199317306439536737340",
"63402322332970091083374365142168087834",
"148766832479749979051371985437001528599",
"73483515630809540738173189371488866248",
"194672309773591208487043143216315158817",
"297112394522946622434949828139654916594",
"244818779082737381344270774694041910062",
"33549209389586948468046774034633659981",
"13232326262678211102770273729109768687",
"40952600223458589525804228033399303341",
"302938871845412863344795683093534939051",
"327734302896597856049413466144726199851",
"247929450359484308090598863689234048064",
"280228242888316317371051510841216734225",
"205825520290612569294355843705773521241",
"160659392089347404431713992538062975838",
"85127213734390330928312802721021947945",
"20082655184044520517042787132516661218",
"203210759411149221175317067471502103086",
"56409088770238899365610263477944468518",
"307852368879463270104290127101887680345",
"116341291910085846001534864117980263439",
"253976290781865838467004826620070476793",
"111346728753050067870659299681968939254",
"65985565584167879187762548334373375887",
"217662424499312653151605570881672525741",
"193335266562769754943467405509677311803",
"112138767083257966893292420775738912639"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2022-48502-d1c72bb6"
},
{
"deprecated": false,
"target": {
"function": "ntfs_create_inode",
"file": "fs/ntfs3/inode.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b",
"digest": {
"function_hash": "309180000253928489021520168495708292723",
"length": 10414.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-48502-faebba56"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48502.json"