CVE-2023-52640

Source
https://cve.org/CVERecord?id=CVE-2023-52640
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52640.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-52640
Downstream
Related
Published
2024-04-03T17:00:10.216Z
Modified
2026-04-11T12:46:33.931616Z
Summary
fs/ntfs3: Fix oob in ntfs_listxattr
Details

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: Fix oob in ntfs_listxattr

The length of name cannot exceed the space occupied by ea.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52640.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4534a70b7056fd4b9a1c6db5a4ce3c98546b291e
Fixed
a585faf0591548fe0920641950ebfa8a6eefe1cd
Fixed
6ed6cdbe88334ca3430c5aee7754dc4597498dfb
Fixed
52fff5799e3d1b5803ecd2f5f19c13c65f4f7b23
Fixed
0830c5cf19bdec50d0ede4755ddc463663deb21c
Fixed
731ab1f9828800df871c5a7ab9ffe965317d3f15

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52640.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
5.15.150
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.80
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.19
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.7.7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52640.json"