Description
In the Linux kernel, the following vulnerability has been resolved:

ntfs: reject invalid empty mapping pairs

Reject an attribute with empty mapping pairs if it has inconsistent
highest VCN and size.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is in the Linux kernel’s NTFS driver. It fails to reject an attribute that contains empty mapping pairs when its highest VCN and size are inconsistent. This input validation flaw could lead to the kernel incorrectly processing the attribute, which may result in kernel instability or denial of service. The flaw is identified as a classic failure of input validation, listed as CWE-130.

Affected Systems

Any Linux kernel version that includes the NTFS code path and not yet patched is vulnerable. The advisory lists a generic Linux kernel product with no specific version limits, implying that all kernels containing the NTFS code path and not yet patched are affected.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low probability of exploitation in the wild. Based on the description, the likely attack vector is mounting an NTFS volume that contains a malformed attribute; the attacker would need to supply such a volume to trigger the issue. The CVE does not report any publicly available exploits at this time.

Generated by OpenCVE AI on September 15, 2026 at 21:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the upstream patch that adds validation for empty mapping pairs in the NTFS driver.
  • If an immediate kernel upgrade is not possible, rebuild the kernel with NTFS support disabled by setting CONFIG_NTFS_FS=n.
  • After applying the patch or disabling NTFS, remount existing NTFS volumes to ensure the driver rejects malformed attributes.

Generated by OpenCVE AI on September 15, 2026 at 21:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-130
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid empty mapping pairs Reject an attribute with empty mapping pairs if it has inconsistent highest VCN and size.
Title ntfs: reject invalid empty mapping pairs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:31:51.266Z

Reserved: 2026-09-11T19:38:34.735Z

Link: CVE-2026-89613

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:46.433

Modified: 2026-09-13T07:17:26.840

Link: CVE-2026-89613

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:14Z

Links: CVE-2026-89613 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses
  • CWE-130

    Improper Handling of Length Parameter Inconsistency