In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: validate BOOT sectors_per_clusters
When the NTFS BOOT sectors_per_clusters field is > 0x80, it represents a shift value. Make sure that the shift value is not too large before using it (NTFS max cluster size is 2MB). Return -EVINVAL if it too large.
This prevents negative shift values and shift values that are larger than the field size.
Prevents this UBSAN error:
UBSAN: shift-out-of-bounds in ../fs/ntfs3/super.c:673:16 shift exponent -192 is negative
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfo-common-aarch64Upgrade kernelUpgrade kernel-tools-debuginfoUpgrade kernel-headersUpgrade kernel-tools-develUpgrade kernel-develUpgrade kernel-debuginfoUpgrade perfUpgrade bpftool-debuginfoUpgrade bpftoolUpgrade perf-debuginfoUpgrade kernel-livepatch-5.15.50-23.125Upgrade kernel-debuginfo-common-x86_64Upgrade kernel-toolsUpgrade python-perfUpgrade python-perf-debuginfo | May 22, 2025 | Feb 26, 2025 |
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-azure-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-nvidiaUpgrade linux-ibmUpgrade linux-gkeopUpgrade linux-intel-iotgUpgrade linux-gcpUpgrade linux-gcp-5.15Upgrade linux-oracleUpgrade linux-kvmUpgrade linuxUpgrade linux-raspiUpgrade linux-riscv-5.15Upgrade linux-aws-5.15Upgrade linux-azureUpgrade linux-realtimeUpgrade linux-awsUpgrade linux-lowlatencyUpgrade linux-oracle-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-hwe-5.15Upgrade linux-gke | Mar 19, 2025 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub