CVE-2025-22080

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 16, 2025
Updated: May 6, 2025
CWE ID 190

Summary

CVE-2025-22080 is a vulnerability affecting the Linux kernel's NTFS file system. The issue lies in the function hdr_first_de(), where the variables "de_off" and "used" obtained from the disk may cause integer overflow on 32-bit systems if they exceed UINT_MAX - 16. Consequently, the intended check fails to prevent potential security risks. This vulnerability has been resolved.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share