CVE-2022-50762
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-50762 is a UBSAN (Undefined Behavior Sanitizer) shift-out-of-bounds vulnerability in the Linux kernel's NTFS3 filesystem driver (fs/ntfs3/super.c). The flaw exists in the true_sectors_per_clst() function, where a negative shift exponent (-247) can be used, triggering undefined behavior. It was publicly disclosed on December 24, 2025, and affects Linux kernel versions from 5.19 through at least 6.1.x, with patches available in stable releases 5.15.86, 6.0.16, 6.1.2, and 6.2. The ENISA/EUVD base score is listed as 0.0, and no CVSS score has been formally assigned by NVD at this time (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The vulnerability is classified as a shift-out-of-bounds issue (CWE-1335: Incorrect Bitwise Shift of Integer) in fs/ntfs3/super.c at line 675. When the true_sectors_per_clst() function processes a malformed or crafted NTFS volume, it can receive a negative value as a shift exponent, which constitutes undefined behavior under the C standard and is flagged by UBSAN. The bug was originally discovered via syzbot (Google's kernel fuzzing infrastructure), which reported the UBSAN error with shift exponent -247. Exploitation would require the ability to mount or interact with a specially crafted NTFS3 filesystem image (Red Hat Bugzilla, Red Hat Advisory).

Impact

The primary impact is a kernel-level undefined behavior condition that could lead to unpredictable system behavior, potential denial of service (kernel panic or crash), or, in edge cases, memory corruption when a malicious or malformed NTFS3 filesystem image is processed. The vulnerability is confined to systems where the NTFS3 driver is in use and a user or process can trigger filesystem mounting. There is no current evidence of privilege escalation or remote code execution being achievable through this flaw (Red Hat Bugzilla).

Mitigation and workarounds

The Linux kernel stable releases 5.15.86, 6.0.16, 6.1.2, and 6.2 contain the fix for this vulnerability. Users should update their Linux kernel to one of these patched versions or later. As a workaround, administrators can prevent loading of the NTFS3 kernel module (ntfs3) on systems where NTFS3 filesystem support is not required, using module blacklisting (echo 'blacklist ntfs3' >> /etc/modprobe.d/blacklist.conf). Red Hat has tracked this issue in their security response process (Red Hat Bugzilla, Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management