Impact
The flaw occurs in the MS‑NTFS filesystem driver in the Linux kernel. The bitmap size is determined at mount time and is independent from the actual cluster count on the disk. When the bitmap is larger than the volume’s cluster layout the allocator scans past the end of the array. Extending a file triggers this out‑of‑bounds read, which KASAN reports. This read is a classic out‑of‑bounds buffer access (CWE‑125) and may expose kernel memory or cause a crash; the vulnerability does not allow arbitrary code execution.
Affected Systems
All Linux kernels that ship with an unpatched ntfs module are affected. Volumes whose bitmap exceeds the cluster count trigger the issue; volumes with proper bitmaps remain unaffected after the patch.
Risk and Exploitability
The CVSS score of 9.8 indicates high severity. EPSS is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to require local privilege or access to a system that mounts a malicious NTFS volume and can manipulate files on it. Consequently, while the potential impact is severe, the overall risk to systems without such an attack vector remains low to moderate, with the primary concern being a possible kernel crash or data disclosure if the conditions are met.
OpenCVE Enrichment