CVE-2025-22080

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Prevent integer overflow in hdr_first_de() The "de_off" and "used" variables come from the disk so they both need to check. The problem is that on 32bit systems if they're both greater than UINT_MAX - 16 then the check does work as intended because of an integer overflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

06 May 2025, 16:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-190
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/201a2bdda13b619c4927700ffe47d387a30ced50 - () https://git.kernel.org/stable/c/201a2bdda13b619c4927700ffe47d387a30ced50 - Patch
References () https://git.kernel.org/stable/c/6bb81b94f7a9cba6bde9a905cef52a65317a8b04 - () https://git.kernel.org/stable/c/6bb81b94f7a9cba6bde9a905cef52a65317a8b04 - Patch
References () https://git.kernel.org/stable/c/85615aa442830027923fc690390fa74d17b36ae1 - () https://git.kernel.org/stable/c/85615aa442830027923fc690390fa74d17b36ae1 - Patch
References () https://git.kernel.org/stable/c/b9982065b82b4177ba3a7a72ce18c84921f7494d - () https://git.kernel.org/stable/c/b9982065b82b4177ba3a7a72ce18c84921f7494d - Patch
References () https://git.kernel.org/stable/c/f6d44b1aa46d317e52c21fb9314cfb20dd69e7b0 - () https://git.kernel.org/stable/c/f6d44b1aa46d317e52c21fb9314cfb20dd69e7b0 - Patch
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: fs/ntfs3: Evitar el desbordamiento de enteros en hdr_first_de(). Las variables "de_off" y "used" provienen del disco, por lo que ambas deben comprobarse. El problema radica en que, en sistemas de 32 bits, si ambas son mayores que UINT_MAX - 16, la comprobación no funciona correctamente debido a un desbordamiento de enteros.
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

16 Apr 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-16 15:16

Updated : 2025-05-06 16:40


NVD link : CVE-2025-22080

Mitre link : CVE-2025-22080

CVE.ORG link : CVE-2025-22080


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-190

Integer Overflow or Wraparound