CVE-2026-89617
Received Received - Intake

Buffer Overflow in Linux Kernel NTFS3

Vulnerability report for CVE-2026-89617, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate dirty page table on log replay Each DIR_PAGE_ENTRY ends in a page_lcns[] array whose length is the on-disk lcns_follow field. check_rstbl() validates the table bookkeeping but never checks that this array fits in the entry, so a crafted lcns_follow lets the v0->v1 conversion memmove and later replay passes run off the entry. Add check_dp_table() to reject, right after check_rstbl(), any entry larger than its size claims via struct_size() (the same expression used to allocate these entries, so the check is overflow-safe by construction). All consumers can then trust lcns_follow as the real capacity. This covers every page_lcns[] access whose index is bounded by the entry itself (the conversion memmove, the HotFix store via find_dp(), and the self-bounded scan loops). Accesses whose index comes from the log record need a separate bound and are handled in a follow-up patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper validation of a dirty page table during log replay in the NTFS3 filesystem. A crafted lcns_follow value in a DIR_PAGE_ENTRY allows a memmove operation to exceed the entry's bounds, potentially leading to memory corruption or other security issues.

Detection Guidance

This vulnerability affects the Linux kernel's NTFS3 filesystem driver. Detection requires checking kernel versions and filesystem operations. Use 'uname -a' to check kernel version and 'mount | grep ntfs' to verify NTFS3 usage. Monitor kernel logs for filesystem errors or crashes.

Impact Analysis

If exploited, this vulnerability could allow an attacker to cause memory corruption, crash the system, or potentially execute arbitrary code with kernel privileges. It specifically affects systems using the NTFS3 filesystem with crafted filesystem images.

Compliance Impact

This vulnerability affects compliance with standards like GDPR and HIPAA by potentially allowing unauthorized access to sensitive data stored in NTFS3 file systems. A crafted lcns_follow value could lead to memory corruption, enabling attackers to read or modify data improperly. This could violate data integrity and confidentiality requirements under GDPR and HIPAA.

Mitigation Strategies

Update the Linux kernel to the latest stable version that includes the fix. Avoid using NTFS3 filesystem until patched. If NTFS3 is required, consider using alternative filesystems like NTFS-3G as a temporary workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89617. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart