Description
In the Linux kernel, the following vulnerability has been resolved:

ntfs: reject invalid MFT LCNs from boot sector

The NTFS boot sector stores the MFT and MFTMirr locations as unsigned
64-bit LCNs, but parse_ntfs_boot_sector() decoded them into an s64.

A crafted high-bit value could therefore become negative and pass
the existing upper-bound check. The invalid value then propagated into
the MFT zone allocator and could result in an out-of-bounds access to
lcn_empty_bits_per_page.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds memory access
Action: Apply patch
AI Analysis

Impact

The Linux kernel NTFS parser misinterprets 64-bit logical cluster numbers from the boot sector as signed values. A crafted high-bit value becomes negative, bypassing the upper-bound check and propagating into the MFT zone allocator, which can cause out-of-bounds access of a kernel array. This flaw can corrupt memory, potentially leading to a crash or information disclosure. The vulnerability is classified as a classic out-of-bounds read/write flaw identified by CWE-787.

Affected Systems

Linux kernel releases before commit 8f8420b68a6f05ca2b03779d8208814ec539b9e5 are affected. Distributions based on those kernels without the patch are vulnerable.

Risk and Exploitability

The CVSS score of 4.7 indicates low-to-medium severity. The EPSS score is <1%, indicating a very low exploitation probability, and the issue is not listed in the CISA KEV catalog. Exploitation requires a crafted NTFS boot sector that gets parsed, local or privileged access to a malicious NTFS volume.

Generated by OpenCVE AI on September 13, 2026 at 05:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Linux kernel that incorporates the fix from commit 8f8420b68a6f05ca2b03779d8208814ec539b9e5.
  • If a kernel update cannot be applied immediately, disable NTFS support or restrict mount access to trusted users to limit exposure.
  • If NTFS support is required, mount NTFS volumes with the read-only option and ensure only trusted origins are used.

Generated by OpenCVE AI on September 13, 2026 at 05:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid MFT LCNs from boot sector The NTFS boot sector stores the MFT and MFTMirr locations as unsigned 64-bit LCNs, but parse_ntfs_boot_sector() decoded them into an s64. A crafted high-bit value could therefore become negative and pass the existing upper-bound check. The invalid value then propagated into the MFT zone allocator and could result in an out-of-bounds access to lcn_empty_bits_per_page.
Title ntfs: reject invalid MFT LCNs from boot sector
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:31:50.050Z

Reserved: 2026-09-11T19:38:34.734Z

Link: CVE-2026-89612

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:46.313

Modified: 2026-09-13T07:17:26.730

Link: CVE-2026-89612

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:13Z

Links: CVE-2026-89612 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T05:45:18Z

Weaknesses