CVE-2026-89614
Received Received - Intake

NTFS Free-Cluster Bitmap Out-of-Bounds Read

Vulnerability report for CVE-2026-89614, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the free-cluster bitmap scan to the volume vol->lcn_empty_bits_per_page is sized from vol->nr_clusters at mount, but ntfs_cluster_alloc() bounds its scan of that array by the size of $Bitmap. Those are independent on-disk quantities and the mount-time check only rejects a $Bitmap that is too small, so an image whose $Bitmap covers more clusters than the volume has lets the scan index past the array. A run whose LCN lies in that gap takes the allocator straight there, since the caller passes the file's own last LCN as its locality hint. KASAN reports a slab out-of-bounds read when a file on such a volume is extended. Clamp the scan to what that array covers, mirroring the max_index calculation the mount-time scan already uses, and reject a decoded LCN at or beyond nr_clusters in the mapping pairs decoder. Conforming volumes are unaffected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a bounds checking issue in the NTFS file system. The free-cluster bitmap scan in ntfs_cluster_alloc() can exceed the allocated array size due to mismatched on-disk quantities. Specifically, the $Bitmap size and volume cluster count are independent, allowing a scan to index past the array when the $Bitmap covers more clusters than the volume. This leads to a slab out-of-bounds read when a file is extended, triggering KASAN errors.

Detection Guidance

This vulnerability is specific to the Linux kernel's NTFS implementation and requires examining filesystem structures. Detection involves checking for malformed NTFS volumes with a $Bitmap larger than the volume's cluster count. No direct commands are provided in the context, but you may inspect NTFS volumes using tools like 'ntfsfix' or 'ntfsinfo' from ntfs-3g utilities. Kernel logs or KASAN reports may also indicate slab out-of-bounds reads during file operations on affected volumes.

Impact Analysis

This vulnerability could allow an attacker to trigger a kernel memory corruption issue by exploiting a maliciously crafted NTFS volume. This might lead to system crashes, data corruption, or potential privilege escalation if exploited. Users running affected Linux kernel versions with NTFS support could be impacted if they mount untrusted NTFS images.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a low-level Linux kernel issue related to memory safety in NTFS file system operations, which could lead to data corruption or crashes but does not inherently impact data privacy or security controls required by these regulations.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for CVE-2026-89614. Conforming volumes are unaffected, so standard kernel updates should resolve the issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89614. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart