Junglewise Threat Intelligence

CVE-2022-50841: Linux kernel NTFS3 integer overflow in attribute parsing

CVE-2022-50841 · Severity: high · CVSS 7.8 · Published 2025-12-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A flaw in the Linux kernel's NTFS3 filesystem driver allows a specially crafted NTFS disk image to trigger an integer overflow when parsing file attributes, leading to out-of-bounds memory access. An attacker could mount a malicious NTFS volume to cause a denial of service (kernel crash) or potentially read/write sensitive kernel memory.

Technical details

The vulnerability is an integer overflow in the fs/ntfs3 MFT (Master File Table) attribute parsing code, specifically in the mi_enum_attr function. When processing an attribute with a very large size value (e.g., 0xffffff7f), the offset addition can overflow, bypassing the used size check and allowing access to out-of-bounds memory via Add2Ptr(attr, asize). The attack requires the attacker to supply a crafted NTFS filesystem image, which can be mounted by any user with mount privileges (or via auto-mount on removable media). The result is a kernel page fault (oops) leading to denial of service; privilege escalation or information disclosure may be possible depending on kernel configuration. A patch adding proper overflow checks has been committed to resolve this issue.

Affected products

  • Linux Linux Kernel 5.19.0 and possibly earlier versions

Timeline

  • 2025-12-30: disclosed: Published in NVD
  • patched: Overflow check added to fs/ntfs3 attribute parsing

Related threats