CVE-2026-89781
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-89781, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() read_log_rec_buf() copies a log record into a caller buffer starting at u32 off = lsn_to_page_off(log, lsn) + log->record_header_len; log->record_header_len (and log->data_off, used for the following pages) comes verbatim from the on-disk restart area and is only checked for 8-byte alignment in is_rst_area_valid(), so off can exceed log->page_size. "tail = log->page_size - off" then underflows and memcpy() reads past the page_size-sized buffer returned by read_log_page(), spilling adjacent slab memory into the replay buffer. This is reachable by mounting a crafted NTFS image: BUG: KASAN: slab-out-of-bounds in read_log_rec_buf+0x216/0x580 Read of size 64 at addr ffff88800a877ff8 by task exploit/127 read_log_rec_buf fs/ntfs3/fslog.c:2299 log_replay fs/ntfs3/fslog.c:4216 ntfs_loadlog_and_replay fs/ntfs3/fsntfs.c:324 ntfs_fill_super fs/ntfs3/super.c:1392 get_tree_bdev_flags fs/super.c:1694 __x64_sys_mount fs/namespace.c:4360 The buggy address is located 4088 bytes to the right of the 4096-byte region [ffff88800a876000, ffff88800a877000) Reject an in-page offset outside the current page before the copy. [almaz.alexandrovich@paragon-software.com: replaced the >= sign with >]

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
Linux Linux b46acd6a6a627d876898e1c84d3f84902264b445
Linux Linux b46acd6a6a627d876898e1c84d3f84902264b445
Linux Linux b46acd6a6a627d876898e1c84d3f84902264b445
Linux Linux b46acd6a6a627d876898e1c84d3f84902264b445
Linux Linux b46acd6a6a627d876898e1c84d3f84902264b445
Linux Linux b46acd6a6a627d876898e1c84d3f84902264b445
Linux Linux b46acd6a6a627d876898e1c84d3f84902264b445
Linux Linux 5.15

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability in the NTFS3 filesystem driver. It involves an out-of-bounds read in the read_log_rec_buf() function. The issue occurs when copying a log record from disk into memory. The function calculates an offset using untrusted data from the disk, which can exceed the page size. This causes a negative value when calculating remaining space, leading to a memcpy() operation reading past the allocated buffer and into adjacent memory.

Detection Guidance

This vulnerability is specific to the Linux kernel's NTFS3 driver and requires mounting a crafted NTFS image to trigger. Detection involves checking for signs of exploitation or vulnerable kernel versions. Monitor system logs for KASAN slab-out-of-bounds errors or unusual NTFS mount operations. Use commands like 'dmesg | grep -i kasan' or 'journalctl -k | grep -i ntfs3' to check for related errors.

Impact Analysis

An attacker could exploit this by mounting a specially crafted NTFS filesystem image. This could lead to memory corruption, crashes, or potentially arbitrary code execution on the system. The vulnerability allows reading adjacent slab memory, which might expose sensitive data or enable further attacks.

Mitigation Strategies

Apply the latest Linux kernel patches that address this issue. If using a vulnerable kernel version, avoid mounting untrusted NTFS images until patched. Update the NTFS3 driver if your distribution provides a separate package. Monitor vendor advisories for updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89781. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart