{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2022-50262","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-09-15T13:58:00.974Z","datePublished":"2025-09-15T14:20:58.578Z","dateUpdated":"2026-05-11T19:15:55.149Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-05-11T19:15:55.149Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Validate BOOT record_size\n\nWhen the NTFS BOOT record_size field < 0, it represents a\nshift value. However, there is no sanity check on the shift result\nand the sbi->record_bits calculation through blksize_bits() assumes\nthe size always > 256, which could lead to NPD while mounting a\nmalformed NTFS image.\n\n[  318.675159] BUG: kernel NULL pointer dereference, address: 0000000000000158\n[  318.675682] #PF: supervisor read access in kernel mode\n[  318.675869] #PF: error_code(0x0000) - not-present page\n[  318.676246] PGD 0 P4D 0\n[  318.676502] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[  318.676934] CPU: 0 PID: 259 Comm: mount Not tainted 5.19.0 #5\n[  318.677289] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu.org 04/01/2014\n[  318.678136] RIP: 0010:ni_find_attr+0x2d/0x1c0\n[  318.678656] Code: 89 ca 4d 89 c7 41 56 41 55 41 54 41 89 cc 55 48 89 fd 53 48 89 d3 48 83 ec 20 65 48 8b 04 25 28 00 00 00 48 89 44 24 180\n[  318.679848] RSP: 0018:ffffa6c8c0297bd8 EFLAGS: 00000246\n[  318.680104] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000080\n[  318.680790] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\n[  318.681679] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\n[  318.682577] R10: 0000000000000000 R11: 0000000000000005 R12: 0000000000000080\n[  318.683015] R13: ffff8d5582e68400 R14: 0000000000000100 R15: 0000000000000000\n[  318.683618] FS:  00007fd9e1c81e40(0000) GS:ffff8d55fdc00000(0000) knlGS:0000000000000000\n[  318.684280] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[  318.684651] CR2: 0000000000000158 CR3: 0000000002e1a000 CR4: 00000000000006f0\n[  318.685623] Call Trace:\n[  318.686607]  <TASK>\n[  318.686872]  ? ntfs_alloc_inode+0x1a/0x60\n[  318.687235]  attr_load_runs_vcn+0x2b/0xa0\n[  318.687468]  mi_read+0xbb/0x250\n[  318.687576]  ntfs_iget5+0x114/0xd90\n[  318.687750]  ntfs_fill_super+0x588/0x11b0\n[  318.687953]  ? put_ntfs+0x130/0x130\n[  318.688065]  ? snprintf+0x49/0x70\n[  318.688164]  ? put_ntfs+0x130/0x130\n[  318.688256]  get_tree_bdev+0x16a/0x260\n[  318.688407]  vfs_get_tree+0x20/0xb0\n[  318.688519]  path_mount+0x2dc/0x9b0\n[  318.688877]  do_mount+0x74/0x90\n[  318.689142]  __x64_sys_mount+0x89/0xd0\n[  318.689636]  do_syscall_64+0x3b/0x90\n[  318.689998]  entry_SYSCALL_64_after_hwframe+0x63/0xcd\n[  318.690318] RIP: 0033:0x7fd9e133c48a\n[  318.690687] Code: 48 8b 0d 11 fa 2a 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 49 89 ca b8 a5 00 00 008\n[  318.691357] RSP: 002b:00007ffd374406c8 EFLAGS: 00000202 ORIG_RAX: 00000000000000a5\n[  318.691632] RAX: ffffffffffffffda RBX: 0000564d0b051080 RCX: 00007fd9e133c48a\n[  318.691920] RDX: 0000564d0b051280 RSI: 0000564d0b051300 RDI: 0000564d0b0596a0\n[  318.692123] RBP: 0000000000000000 R08: 0000564d0b0512a0 R09: 0000000000000020\n[  318.692349] R10: 00000000c0ed0000 R11: 0000000000000202 R12: 0000564d0b0596a0\n[  318.692673] R13: 0000564d0b051280 R14: 0000000000000000 R15: 00000000ffffffff\n[  318.693007]  </TASK>\n[  318.693271] Modules linked in:\n[  318.693614] CR2: 0000000000000158\n[  318.694446] ---[ end trace 0000000000000000 ]---\n[  318.694779] RIP: 0010:ni_find_attr+0x2d/0x1c0\n[  318.694952] Code: 89 ca 4d 89 c7 41 56 41 55 41 54 41 89 cc 55 48 89 fd 53 48 89 d3 48 83 ec 20 65 48 8b 04 25 28 00 00 00 48 89 44 24 180\n[  318.696042] RSP: 0018:ffffa6c8c0297bd8 EFLAGS: 00000246\n[  318.696531] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000080\n[  318.698114] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\n[  318.699286] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\n[  318.699795] R10: 0000000000000000 R11: 0000000000000005 R12: 0000000000000080\n[  318.700236] R13: ffff8d5582e68400 R14: 0000000000000100 R15: 0000000000000000\n[  318.700973] FS:  00007fd9e1c81e40(0000) GS:ffff8d55fdc00000(0000) knlGS:0000000000000000\n[\n---truncated---"}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ntfs3/super.c"],"versions":[{"version":"4534a70b7056fd4b9a1c6db5a4ce3c98546b291e","lessThan":"af7a195deae349f15baa765d000a5188920d61dd","status":"affected","versionType":"git"},{"version":"4534a70b7056fd4b9a1c6db5a4ce3c98546b291e","lessThan":"8702e0dc987014f6d77740b693340f91344fd0ae","status":"affected","versionType":"git"},{"version":"4534a70b7056fd4b9a1c6db5a4ce3c98546b291e","lessThan":"db91a9c59162a9c56792ded88160442c0a2dabd5","status":"affected","versionType":"git"},{"version":"4534a70b7056fd4b9a1c6db5a4ce3c98546b291e","lessThan":"0b66046266690454dc04e6307bcff4a5605b42a1","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ntfs3/super.c"],"versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","status":"unaffected","versionType":"semver"},{"version":"5.15.87","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.0.17","lessThanOrEqual":"6.0.*","status":"unaffected","versionType":"semver"},{"version":"6.1.3","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"5.15.87"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.0.17"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.1.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/af7a195deae349f15baa765d000a5188920d61dd"},{"url":"https://git.kernel.org/stable/c/8702e0dc987014f6d77740b693340f91344fd0ae"},{"url":"https://git.kernel.org/stable/c/db91a9c59162a9c56792ded88160442c0a2dabd5"},{"url":"https://git.kernel.org/stable/c/0b66046266690454dc04e6307bcff4a5605b42a1"}],"title":"fs/ntfs3: Validate BOOT record_size","x_generator":{"engine":"bippy-1.2.0"}}}}