CVE-2026-89611
Received Received - Intake

NTFS Attribute Offset Validation Flaw

Vulnerability report for CVE-2026-89611, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ntfs: validate non-resident attribute offsets ntfs_attr_update_meta() shifts the attribute name when converting between non-sparse and sparse attributes. Converting to sparse also adds the compressed_size field before the name and mapping pairs, requiring eight additional bytes in the attribute record. However, the validator does not check that name_offset is within safe boundaries for these operations or that the additional space is available. A malicious MFT record could set name_offset such that: 1. The name is positioned at the very end of a non-sparse attribute. Converting to sparse would shift the name forward by 8 bytes, writing beyond the attribute boundary. 2. The name overlaps with the mapping pairs, causing corruption during conversion. Add validation to ensure: - For named attributes, name_offset is within valid bounds - Name does not extend beyond the attribute or overlap with mapping pairs - For non-sparse, non-compressed attributes, eight bytes are available after mapping_pairs_offset for the compressed_size field The space check also covers unnamed attributes, for which name_offset = 0 is valid and no name range needs to be checked.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux_kernel ntfs *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper validation of non-resident attribute offsets in NTFS filesystems. When converting between non-sparse and sparse attributes, the validator fails to ensure name_offset is within safe boundaries. This can lead to the name being shifted beyond attribute limits or overlapping with mapping pairs, causing corruption or out-of-bounds writes during conversion.

Detection Guidance

This vulnerability is specific to the Linux kernel's NTFS implementation and requires kernel-level inspection. Detection involves checking kernel logs for filesystem errors or corruption related to NTFS attributes. Use commands like dmesg | grep ntfs or journalctl -k | grep ntfs to review kernel messages for suspicious activity. Additionally, monitor for filesystem corruption or crashes during NTFS operations.

Impact Analysis

This vulnerability could allow an attacker with local filesystem access to corrupt NTFS metadata, potentially leading to data loss, filesystem unavailability, or privilege escalation. Systems using NTFS filesystems with sparse files are most at risk.

Compliance Impact

This vulnerability could potentially lead to data corruption or unauthorized access in NTFS file systems, which may impact compliance with data integrity and security requirements under standards like GDPR and HIPAA. Unauthorized modifications or corruption of file attributes could result in data breaches or loss of sensitive information, violating regulatory obligations for data protection and integrity.

Mitigation Strategies

Apply the latest Linux kernel updates to patch this vulnerability. If immediate patching is not possible, avoid using NTFS filesystems or restrict access to untrusted filesystems. Monitor for signs of exploitation such as filesystem corruption or crashes. Ensure backups are up to date to recover from potential data corruption.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89611. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart