Impact
The Linux kernel NTFS module parses the boot sector of an NTFS volume and treats the MFT and MFTMirr locations, stored as unsigned 64‑bit logical cluster numbers, as signed 64‑bit values. If a crafted high‑bit value becomes negative and passes the existing upper‑bound check, the negative index is then used by the MFT zone allocator, producing an out‑of‑bounds access to the array lcn_empty_bits_per_page. This flaw (CWE‑787) can corrupt kernel memory and potentially lead to a crash or information disclosure.
Affected Systems
Any Linux kernel release that predates the inclusion of commit 8f8420b68a6f05ca2b03779d8208814ec539b9e5 is vulnerable. Distributions built on those kernels without applying the patch remain affected. The vulnerability applies to all components that enable NTFS support in the kernel.
Risk and Exploitability
The CVSS score of 9.8 signifies an Extremely High severity. The EPSS score of < 1% indicates that, while the flaw is critical, the likelihood of exploitation in the wild is low. The issue is not listed in the CISA KEV catalog. Based on the description, exploitation would require a malicious NTFS boot sector that the kernel parses, which generally demands local or privileged access to mount or otherwise inject the boot sector into the kernel’s parsing path.
OpenCVE Enrichment