In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: validate BOOT sectors_per_clusters
When the NTFS BOOT sectors_per_clusters field is > 0x80, it represents a shift value. Make sure that the shift value is not too large before using it (NTFS max cluster size is 2MB). Return -EVINVAL if it too large.
This prevents negative shift values and shift values that are larger than the field size.
Prevents this UBSAN error:
UBSAN: shift-out-of-bounds in ../fs/ntfs3/super.c:673:16 shift exponent -192 is negative
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-tools-debuginfoUpgrade kernel-debuginfo-common-aarch64Upgrade bpftoolUpgrade kernel-debuginfoUpgrade kernelUpgrade perfUpgrade kernel-tools-develUpgrade kernel-develUpgrade kernel-headersUpgrade bpftool-debuginfoUpgrade kernel-toolsUpgrade kernel-livepatch-5.15.50-23.125Upgrade python-perfUpgrade python-perf-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade perf-debuginfo | May 22, 2025 | Feb 26, 2025 |
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-azureUpgrade linux-realtimeUpgrade linux-gkeUpgrade linux-awsUpgrade linux-riscv-5.15Upgrade linux-hwe-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-oracle-5.15Upgrade linux-aws-5.15Upgrade linux-lowlatencyUpgrade linux-raspiUpgrade linux-gkeopUpgrade linux-gcpUpgrade linuxUpgrade linux-ibmUpgrade linux-intel-iotg-5.15Upgrade linux-kvmUpgrade linux-intel-iotgUpgrade linux-oracleUpgrade linux-azure-5.15Upgrade linux-nvidiaUpgrade linux-gcp-5.15 | Mar 19, 2025 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub