Description
In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: bound page_lcns[] index by the log record

The copy_lcns loop and the redo shorten loop index page_lcns[] at j + i,
where i runs up to the log record's lcns_follow. That count is checked only
against the record's own length, not the target entry, so check_dp_table()
(which validates the entry's lcns_follow) does not cover it: the copy_lcns
entry may even be freshly allocated after that check, and find_dp() bounds j
but not i. A crafted record thus overflows page_lcns[] of an otherwise valid
entry.

Add dp_range_ok() and reject, before each loop, any record whose run does
not fit the entry. These are the only two page_lcns[] accesses indexed by
the record rather than the entry, so together with the entry validation
every access is now bounded.

[almaz.alexandrovich@paragon-software.com: original patch contained changes to the problem already handled, applied partly]
Published: 2026-09-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Kernel Buffer Overflow
Action: Apply Patch
AI Analysis

Impact

The NTFS3 driver in the Linux kernel performs an improper bounds check on the page_lcns[] array. In the copy_lcns and redo loops, the index is derived from the lcns_follow value found in a log record. The loop bounds are validated only against the length of that record, not against the size of the target entry. Consequently, a crafted log record can overflow page_lcns[] of a valid entry, corrupting kernel memory. Such corruption can lead to privilege escalation or a system crash, because the overflow occurs in privileged kernel space.

Affected Systems

All Linux kernels that include the unpatched NTFS3 code are affected, regardless of distribution. The vulnerability exists in the core kernel, so any kernel version that contains the buggy implementation and lacks the dp_range_ok() bounds check is vulnerable. No specific version numbers are listed; therefore, any kernel prior to the patch commit that introduces the bounds check is considered at risk.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity vulnerability. The EPSS score of less than 1% demonstrates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. Based on the description, the likely attack vector involves crafting a malicious NTFS volume that the kernel processes, typically requiring physical or removable media access or local write privileges. Because the flaw resides in kernel space, a successful exploitation could result in privilege escalation or denial of service.

Generated by OpenCVE AI on September 15, 2026 at 21:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the ntfs3 bounds‑check fix committed by the patch.
  • If an immediate kernel upgrade cannot be performed, unmount or disable all NTFS3 filesystems or the ntfs3 module until the kernel is updated.
  • Alternatively backport the specific commit changes (adding dp_range_ok() and bounds checks) to the running kernel or to the distribution’s kernel patches.

Generated by OpenCVE AI on September 15, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound page_lcns[] index by the log record The copy_lcns loop and the redo shorten loop index page_lcns[] at j + i, where i runs up to the log record's lcns_follow. That count is checked only against the record's own length, not the target entry, so check_dp_table() (which validates the entry's lcns_follow) does not cover it: the copy_lcns entry may even be freshly allocated after that check, and find_dp() bounds j but not i. A crafted record thus overflows page_lcns[] of an otherwise valid entry. Add dp_range_ok() and reject, before each loop, any record whose run does not fit the entry. These are the only two page_lcns[] accesses indexed by the record rather than the entry, so together with the entry validation every access is now bounded. [almaz.alexandrovich@paragon-software.com: original patch contained changes to the problem already handled, applied partly]
Title fs/ntfs3: bound page_lcns[] index by the log record
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:31.040Z

Reserved: 2026-09-11T19:38:34.735Z

Link: CVE-2026-89615

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:46.653

Modified: 2026-09-14T13:19:15.393

Link: CVE-2026-89615

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:15Z

Links: CVE-2026-89615 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses