PT-2025-25983 · Linux+1 · Linux Kernel+1
Published
2022-07-05
·
Updated
2025-07-04
·
CVE-2022-50057
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.18.0-rc3-syzkaller-00016-gb253435746d9
Description
A NULL pointer dereference issue has been identified in the Linux kernel, specifically in the fs/ntfs3 component. This issue occurs when the
ntfs fill super() function is not called, resulting in a NULL pointer being dereferenced. The problem can be triggered by passing incorrect mount parameters, as demonstrated by a Syzbot test. The issue leads to a general protection fault and a null-ptr-deref error.Recommendations
For Linux kernel versions prior to 5.18.0-rc3-syzkaller-00016-gb253435746d9, consider updating to a newer version that includes the fix for the NULL pointer dereference issue in the fs/ntfs3 component. As a temporary workaround, avoid passing incorrect mount parameters to prevent triggering the issue.
Exploit
Fix
Improper Resource Release
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel