{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-22080","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-12-29T08:45:45.815Z","datePublished":"2025-04-16T14:12:29.886Z","dateUpdated":"2026-08-05T11:56:35.647Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:56:35.647Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Prevent integer overflow in hdr_first_de()\n\nThe \"de_off\" and \"used\" variables come from the disk so they both need to\ncheck.  The problem is that on 32bit systems if they're both greater than\nUINT_MAX - 16 then the check does work as intended because of an integer\noverflow."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code is reached only by presenting a crafted NTFS volume to the local kernel as a block device — a USB stick on an automounting kiosk/NAS/infotainment unit, or a loop/NBD-backed image mounted via udisks2 — driving mount(2) and the subsequent index walks in fs/ntfs3/index.c. No network protocol handler is involved, and physical access is not strictly required since loop and network-block-backed images work equally well.\nAC:L - Every input to the wrap — hdr->de_off, hdr->used, hdr->total, the entry size fields, and the attribute-list layout that steers which header escapes index_hdr_check() — is an attacker-chosen byte in the image, so the corruption is deterministic with no race to win and no dependency on kernel memory layout the attacker cannot influence. The 32-bit size_t requirement is a property of the target the attacker selects, and ntfs3 automounting removable NTFS media on 32-bit ARM NAS boxes, media players, and embedded appliances is the driver's canonical deployment rather than a rare configuration.\nPR:N - The attacker needs no account or credential on the target — they only supply the malicious filesystem image, which is then mounted by root, by an automount daemon such as udisks2/systemd, or by a container/VM image-handling service acting on the attacker's data. Every privileged operation along the path is performed by the victim system on the attacker's behalf; where a local account does exist, desktop polkit loop-mount brokering provides the same reach at even lower cost.\nUI:N - On kiosks, NAS appliances, and infotainment systems that automount removable media, inserting the device triggers the mount with no human participation, and the index code runs unattended during mount itself via ntfs_security_init()'s indx_init()/indx_find() on the $SDH/$SII trees rather than waiting for a subsequent file access. In the loop-device scenario the attacker performs the mount themselves, so no separate victim action is required either.\nS:U - The wrapped pointer arithmetic, out-of-bounds reads, and memmove/memcpy writes all occur in kernel heap memory within the same kernel security authority that hosts the vulnerable ntfs3 code. No VM, IOMMU, hypervisor, or sandbox boundary is crossed.\nC:H - The wrapped pointer makes hdr_first_de() return an NTFS_DE outside the index buffer, and because hdr_next_de()'s bound check wraps identically with used near UINT_MAX, the entry walk proceeds past the allocation reading adjacent kernel heap as entry headers. Those bytes are consumed as file names, key_size, and MFT references and handed to userspace through ntfs_dir_emit()/dir_emit() during readdir, and steer de_get_vbn()-driven follow-on reads, making adjacent kernel memory directly observable.\nI:H - The same out-of-bounds entry pointer is passed to the mutation paths — hdr_insert_de() performs memmove(Add2Ptr(before, de_size), before, used - off) and memcpy(before, de, de_size) through it, hdr_delete_de() memmoves through it, and indx_delete_entry() applies le16_sub_cpu()/le32_sub_cpu() to fields at that address — yielding an out-of-bounds write of attacker-chosen bytes into kernel heap adjacent to the MFT-record or index-block allocation. Controlled heap overwrite of that form is a usable memory-corruption primitive for control-flow hijack, and the corrupted headers are additionally written back to disk by indx_write().\nA:H - Dereferencing and walking a pointer built from wrapped 32-bit arithmetic reads and writes past the kmalloc'd index buffer, producing slab corruption and oops/panic (KASAN-class out-of-bounds), and the resulting nonsensical index geometry drives _ntfs_bad_inode()/-EINVAL error paths across the mounted volume. The fault occurs during mount or the first directory operation and can be reproduced on every mount attempt of the crafted image."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ntfs3/ntfs.h"],"versions":[{"version":"60ce8dfde03558bfc290cd915c60fa243ba2ae84","lessThan":"f6d44b1aa46d317e52c21fb9314cfb20dd69e7b0","status":"affected","versionType":"git"},{"version":"60ce8dfde03558bfc290cd915c60fa243ba2ae84","lessThan":"201a2bdda13b619c4927700ffe47d387a30ced50","status":"affected","versionType":"git"},{"version":"60ce8dfde03558bfc290cd915c60fa243ba2ae84","lessThan":"85615aa442830027923fc690390fa74d17b36ae1","status":"affected","versionType":"git"},{"version":"60ce8dfde03558bfc290cd915c60fa243ba2ae84","lessThan":"b9982065b82b4177ba3a7a72ce18c84921f7494d","status":"affected","versionType":"git"},{"version":"60ce8dfde03558bfc290cd915c60fa243ba2ae84","lessThan":"6bb81b94f7a9cba6bde9a905cef52a65317a8b04","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ntfs3/ntfs.h"],"versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","status":"unaffected","versionType":"semver"},{"version":"6.6.87","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.23","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.13.11","lessThanOrEqual":"6.13.*","status":"unaffected","versionType":"semver"},{"version":"6.14.2","lessThanOrEqual":"6.14.*","status":"unaffected","versionType":"semver"},{"version":"6.15","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.6.87"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.12.23"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.13.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.14.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.15"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f6d44b1aa46d317e52c21fb9314cfb20dd69e7b0"},{"url":"https://git.kernel.org/stable/c/201a2bdda13b619c4927700ffe47d387a30ced50"},{"url":"https://git.kernel.org/stable/c/85615aa442830027923fc690390fa74d17b36ae1"},{"url":"https://git.kernel.org/stable/c/b9982065b82b4177ba3a7a72ce18c84921f7494d"},{"url":"https://git.kernel.org/stable/c/6bb81b94f7a9cba6bde9a905cef52a65317a8b04"}],"title":"fs/ntfs3: Prevent integer overflow in hdr_first_de()","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-190","lang":"en","description":"CWE-190 Integer Overflow or Wraparound"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":5.5,"attackVector":"LOCAL","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2025-10-01T16:15:41.224860Z","id":"CVE-2025-22080","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-01T16:15:44.922Z"}}]}}