ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 3 sources: “ZDI Discloses Three Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerabilities” — merged summary and timeline →

ZDI-26-699: Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerability

lowVulnerabilityimportance 15
AI summary · glm-5.3

ZDI-26-699: Linux Kernel NTFS3 out-of-bounds read (CVSS 5.2) lets local low-privileged attackers disclose sensitive information.

ZDI advisory ZDI-26-699 describes an out-of-bounds read in the Linux Kernel NTFS3 driver rated CVSS 5.2. An attacker must already have the ability to execute low-privileged code on the target system to trigger the flaw. Successful exploitation results in information disclosure. No CVE identifier is listed in the advisory.

  • Out-of-bounds read in Linux Kernel NTFS3 driver
  • CVSS 5.2, local information disclosure only
  • Requires prior low-privileged code execution
  • No CVE assigned in advisory text
Full article

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.2.

This source does not provide full text. Read it at zerodayinitiative.com.