CVE-2022-30784: Debian Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only; version 11.0 only
  • Fedoraproject Fedora: version 35 only; version 36 only
  • Tuxera Ntfs-3g: up to and including 2021.8.22

Published 2022-05-26. Last modified 2026-06-17.