Impact
The vulnerability is in the Linux kernel’s NTFS driver. It fails to reject an attribute that contains empty mapping pairs when its highest VCN and size are inconsistent. This input validation flaw could lead to the kernel incorrectly processing the attribute, which may result in kernel instability or denial of service. The flaw is identified as a classic failure of input validation, listed as CWE-130.
Affected Systems
Any Linux kernel version that includes the NTFS code path and not yet patched is vulnerable. The advisory lists a generic Linux kernel product with no specific version limits, implying that all kernels containing the NTFS code path and not yet patched are affected.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low probability of exploitation in the wild. Based on the description, the likely attack vector is mounting an NTFS volume that contains a malformed attribute; the attacker would need to supply such a volume to trigger the issue. The CVE does not report any publicly available exploits at this time.
OpenCVE Enrichment