Impact
The Linux kernel’s NTFS mapping decoder validates only the starting logical cluster number (LCN) of a file run and fails to confirm that the entire run lies within the volume boundary. A malicious NTFS image that contains a mapping pair whose length extends past the end of the volume can cause the kernel to to memory corruption. This flaw is a classic out‑of‑bounds write described as CWE‑787 and can be exploited to elevate privileges to the kernel level.
Affected Systems
All Linux kernel builds that include the unpatched ntfs mapping decoder are affected. This encompasses upstream kernels prior to the boundary‑check patch, as well as custom builds or older kernel releases that have not incorporated the kernel across major distributions, custom kernels, or older kernel versions that lack the patch is vulnerable when the kernel mounts or processes a malicious NTFS filesystem.
Risk and Exploitability
The CVSS score of 9.8 signals a critical impact, while the EPSS score of < 1% indicates a low probability of real‑world exploitation at this time. The vulnerability is not listed in the CISA KEV catalog and no public exploits have been disclosed. The likely attack vector involves providing a specially crafted NTFS volume, typically via removable media or a controllable remote file system mount, to trigger the flaw during NTFS decoding. If successfully triggered, the resulting memory corruption could be leveraged to achieve privilege escalation.
OpenCVE Enrichment