CVE-2022-49762
MEDIUMLinux Kernel - Denial of Service via ATTR_RECORD Integer Overflow in NTFS
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: ntfs: check overflow when iterating ATTR_RECORDs Kernel iterates over ATTR_RECORDs in mft record in ntfs_attr_find(). Because the ATTR_RECORDs are next to each other, kernel can get the next ATTR_RECORD from end address of current ATTR_RECORD, through current ATTR_RECORD length field. The problem is that during iteration, when kernel calculates the end address of current ATTR_RECORD, kernel may trigger an integer overflow bug in executing `a = (ATTR_RECORD*)((u8*)a + le32_to_cpu(a->length))`. This may wrap, leading to a forever iteration on 32bit systems. This patch solves it by adding some checks on calculating end address of current ATTR_RECORD during iteration.
References (8)
Core 8
Core References
Scores
CVSS v3
5.5
EPSS
0.0021
EPSS Percentile
10.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
Status
published
Products (26)
linux/Kernel
2.6.12 - 4.9.334linux
linux/Kernel
4.10.0 - 4.14.300linux
linux/Kernel
4.15.0 - 4.19.267linux
linux/Kernel
4.20.0 - 5.4.225linux
linux/Kernel
5.11.0 - 5.15.80linux
linux/Kernel
5.16.0 - 6.0.10linux
linux/Kernel
5.5.0 - 5.10.156linux
Linux/Linux
< 2.6.12
Linux/Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 45683723f6b53e39e8a4cec0894e61fd6ec71989
Linux/Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 5559eb5809353a83a40a1e4e7f066431c7b83020
... and 16 more
Published
May 01, 2025
Tracked Since
Feb 18, 2026