Description
In the Linux kernel, the following vulnerability has been resolved:

ntfs: reject invalid MFT LCNs from boot sector

The NTFS boot sector stores the MFT and MFTMirr locations as unsigned
64-bit LCNs, but parse_ntfs_boot_sector() decoded them into an s64.

A crafted high-bit value could therefore become negative and pass
the existing upper-bound check. The invalid value then propagated into
the MFT zone allocator and could result in an out-of-bounds access to
lcn_empty_bits_per_page.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds kernel memory access leading to potential crash or information disclosure
Action: Patch Now
AI Analysis

Impact

The Linux kernel NTFS module parses the boot sector of an NTFS volume and treats the MFT and MFTMirr locations, stored as unsigned 64‑bit logical cluster numbers, as signed 64‑bit values. If a crafted high‑bit value becomes negative and passes the existing upper‑bound check, the negative index is then used by the MFT zone allocator, producing an out‑of‑bounds access to the array lcn_empty_bits_per_page. This flaw (CWE‑787) can corrupt kernel memory and potentially lead to a crash or information disclosure.

Affected Systems

Any Linux kernel release that predates the inclusion of commit 8f8420b68a6f05ca2b03779d8208814ec539b9e5 is vulnerable. Distributions built on those kernels without applying the patch remain affected. The vulnerability applies to all components that enable NTFS support in the kernel.

Risk and Exploitability

The CVSS score of 9.8 signifies an Extremely High severity. The EPSS score of < 1% indicates that, while the flaw is critical, the likelihood of exploitation in the wild is low. The issue is not listed in the CISA KEV catalog. Based on the description, exploitation would require a malicious NTFS boot sector that the kernel parses, which generally demands local or privileged access to mount or otherwise inject the boot sector into the kernel’s parsing path.

Generated by OpenCVE AI on September 15, 2026 at 21:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that contains commit 8f8420b68a6f05ca2b03779d8208814ec539b9e5 or a later release that incorporates the fix.
  • If a kernel upgrade cannot be done immediately, disable NTFS support in the kernel configuration (for example, by removing the ntfs module or setting the kernel config option to off) or restrict NTFS mount operations to trusted users only.
  • When NTFS support must remain, mount the filesystem with the read‑only option and ensure volumes originate from trusted sources.

Generated by OpenCVE AI on September 15, 2026 at 21:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid MFT LCNs from boot sector The NTFS boot sector stores the MFT and MFTMirr locations as unsigned 64-bit LCNs, but parse_ntfs_boot_sector() decoded them into an s64. A crafted high-bit value could therefore become negative and pass the existing upper-bound check. The invalid value then propagated into the MFT zone allocator and could result in an out-of-bounds access to lcn_empty_bits_per_page.
Title ntfs: reject invalid MFT LCNs from boot sector
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:31:50.050Z

Reserved: 2026-09-11T19:38:34.734Z

Link: CVE-2026-89612

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:46.313

Modified: 2026-09-13T07:17:26.730

Link: CVE-2026-89612

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:13Z

Links: CVE-2026-89612 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses