ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 3 sources: “ZDI Discloses Three Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerabilities” — merged summary and timeline →

ZDI-26-698: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

lowVulnerabilityimportance 15
AI summary · glm-5.3

ZDI-26-698: Linux Kernel NTFS3 out-of-bounds read (CVSS 5.2) allows local attackers to disclose sensitive information on affected systems.

ZDI advisory ZDI-26-698 describes an out-of-bounds read in the Linux Kernel NTFS3 driver rated CVSS 5.2. Exploitation requires the attacker to first obtain the ability to execute low-privileged code on the target. The impact is limited to local information disclosure. No CVE identifier is listed in the advisory.

  • Out-of-bounds read in Linux Kernel NTFS3 driver
  • CVSS 5.2, local information disclosure only
  • Requires prior low-privileged code execution
  • No CVE assigned in advisory text
Full article

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.2.

This source does not provide full text. Read it at zerodayinitiative.com.