Executive brief
A flaw in the Linux kernel's NTFS3 filesystem driver allows a specially crafted NTFS disk image to trigger an integer overflow when parsing file attributes, leading to out-of-bounds memory access. An attacker could mount a malicious NTFS volume to cause a denial of service (kernel crash) or potentially read/write sensitive kernel memory.
Technical details
The vulnerability is an integer overflow in the fs/ntfs3 MFT (Master File Table) attribute parsing code, specifically in the mi_enum_attr function. When processing an attribute with a very large size value (e.g., 0xffffff7f), the offset addition can overflow, bypassing the used size check and allowing access to out-of-bounds memory via Add2Ptr(attr, asize). The attack requires the attacker to supply a crafted NTFS filesystem image, which can be mounted by any user with mount privileges (or via auto-mount on removable media). The result is a kernel page fault (oops) leading to denial of service; privilege escalation or information disclosure may be possible depending on kernel configuration. A patch adding proper overflow checks has been committed to resolve this issue.
Affected products
- Linux Linux Kernel 5.19.0 and possibly earlier versions
Timeline
- 2025-12-30: disclosed: Published in NVD
- patched: Overflow check added to fs/ntfs3 attribute parsing