CVE-2025-22080
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Apr 16, 2025
Updated: May 6, 2025
CWE ID 190
Summary
CVE-2025-22080 is a vulnerability affecting the Linux kernel's NTFS file system. The issue lies in the function hdr_first_de(), where the variables "de_off" and "used" obtained from the disk may cause integer overflow on 32-bit systems if they exceed UINT_MAX - 16. Consequently, the intended check fails to prevent potential security risks. This vulnerability has been resolved.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX