{"id":"CVE-2022-50869","summary":"fs/ntfs3: Fix slab-out-of-bounds in r_page","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Fix slab-out-of-bounds in r_page\n\nWhen PAGE_SIZE is 64K, if read_log_page is called by log_read_rst for\nthe first time, the size of *buffer would be equal to\nDefaultLogPageSize(4K).But for *buffer operations like memcpy,\nif the memory area size(n) which being assigned to buffer is larger\nthan 4K (log-\u003epage_size(64K) or bytes(64K-page_off)), it will cause\nan out of boundary error.\n Call trace:\n  [...]\n  kasan_report+0x44/0x130\n  check_memory_region+0xf8/0x1a0\n  memcpy+0xc8/0x100\n  ntfs_read_run_nb+0x20c/0x460\n  read_log_page+0xd0/0x1f4\n  log_read_rst+0x110/0x75c\n  log_replay+0x1e8/0x4aa0\n  ntfs_loadlog_and_replay+0x290/0x2d0\n  ntfs_fill_super+0x508/0xec0\n  get_tree_bdev+0x1fc/0x34c\n  [...]\n\nFix this by setting variable r_page to NULL in log_read_rst.","modified":"2026-08-12T03:51:27.443385011Z","published":"2025-12-30T12:15:39.879Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50869.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/6d076293e5bffdf897ea5f975669206e09beed6a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bf86a640a34947d92062996e1a75b9cd9d83dd19"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ecfbd57cf9c5ca225184ae266ce44ae473792132"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ed686e7a26dd19ae6b46bb662f735acfa88ff7bc"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50869.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-50869"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"b46acd6a6a627d876898e1c84d3f84902264b445"},{"fixed":"ed686e7a26dd19ae6b46bb662f735acfa88ff7bc"},{"fixed":"bf86a640a34947d92062996e1a75b9cd9d83dd19"},{"fixed":"6d076293e5bffdf897ea5f975669206e09beed6a"},{"fixed":"ecfbd57cf9c5ca225184ae266ce44ae473792132"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50869.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.15.0"},{"fixed":"5.15.87"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.0.17"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.1.0"},{"fixed":"6.1.3"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50869.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}