We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-50057

fs/ntfs3: Fix NULL deref in ntfs_update_mftmirr



Description

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix NULL deref in ntfs_update_mftmirr If ntfs_fill_super() wasn't called then sbi->sb will be equal to NULL. Code should check this ptr before dereferencing. Syzbot hit this issue via passing wrong mount param as can be seen from log below Fail log: ntfs3: Unknown parameter 'iochvrset' general protection fault, probably for non-canonical address 0xdffffc0000000003: 0000 [#1] PREEMPT SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000018-0x000000000000001f] CPU: 1 PID: 3589 Comm: syz-executor210 Not tainted 5.18.0-rc3-syzkaller-00016-gb253435746d9 #0 ... Call Trace: <TASK> put_ntfs+0x1ed/0x2a0 fs/ntfs3/super.c:463 ntfs_fs_free+0x6a/0xe0 fs/ntfs3/super.c:1363 put_fs_context+0x119/0x7a0 fs/fs_context.c:469 do_new_mount+0x2b4/0xad0 fs/namespace.c:3044 do_mount fs/namespace.c:3383 [inline] __do_sys_mount fs/namespace.c:3591 [inline]

Reserved 2025-06-18 | Published 2025-06-18 | Updated 2025-06-18 | Assigner Linux

Product status

Default status
unaffected

82cae269cfa953032fbb8980a7d554d60fb00b17 before 8e8e1a84dac7a3d2b432162a70d7fb6a75960772
affected

82cae269cfa953032fbb8980a7d554d60fb00b17 before bf6089dc01ba3194ab962105d7b85690843c256f
affected

82cae269cfa953032fbb8980a7d554d60fb00b17 before 321460ca3b55f48b3ba6008248264ab2bd6407d9
affected

Default status
affected

5.15
affected

Any version before 5.15
unaffected

5.15.63
unaffected

5.19.4
unaffected

6.0
unaffected

References

git.kernel.org/...c/8e8e1a84dac7a3d2b432162a70d7fb6a75960772

git.kernel.org/...c/bf6089dc01ba3194ab962105d7b85690843c256f

git.kernel.org/...c/321460ca3b55f48b3ba6008248264ab2bd6407d9

cve.org (CVE-2022-50057)

nvd.nist.gov (CVE-2022-50057)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2022-50057

Support options

Helpdesk Chat, Email, Knowledgebase