The vendor explicitly states that these products are not affected by this CVE.
- kernel as a component of Red Hat Enterprise Linux 10
- kernel-64k as a component of Red Hat Enterprise Linux 10
- kernel-64k-core as a component of Red Hat Enterprise Linux 10
- kernel-64k-debug as a component of Red Hat Enterprise Linux 10
- kernel-64k-debug-core as a component of Red Hat Enterprise Linux 10
- kernel-64k-debug-devel as a component of Red Hat Enterprise Linux 10
- kernel-64k-debug-devel-matched as a component of Red Hat Enterprise Linux 10
- kernel-64k-debug-modules as a component of Red Hat Enterprise Linux 10
- kernel-64k-debug-modules-core as a component of Red Hat Enterprise Linux 10
- kernel-64k-debug-modules-extra as a component of Red Hat Enterprise Linux 10
- kernel-64k-devel as a component of Red Hat Enterprise Linux 10
- kernel-64k-devel-matched as a component of Red Hat Enterprise Linux 10
- Summary
- A flaw was found in the NTFS3 filesystem driver of the Linux kernel. This use-after-free vulnerability occurs due to insufficient validation of the index root during NTFS security initialization. A local attacker could exploit this by mounting a specially crafted NTFS filesystem, potentially leading to privilege escalation or a denial of service.
- Remediation
- No remediation text is recorded.
