Impact
The NTFS3 driver in the Linux kernel performs an improper bounds check on the page_lcns[] array. In the copy_lcns and redo loops, the index is derived from the lcns_follow value found in a log record. The loop bounds are validated only against the length of that record, not against the size of the target entry. Consequently, a crafted log record can overflow page_lcns[] of a valid entry, corrupting kernel memory. Such corruption can lead to privilege escalation or a system crash, because the overflow occurs in privileged kernel space.
Affected Systems
All Linux kernels that include the unpatched NTFS3 code are affected, regardless of distribution. The vulnerability exists in the core kernel, so any kernel version that contains the buggy implementation and lacks the dp_range_ok() bounds check is vulnerable. No specific version numbers are listed; therefore, any kernel prior to the patch commit that introduces the bounds check is considered at risk.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability. The EPSS score of less than 1% demonstrates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. Based on the description, the likely attack vector involves crafting a malicious NTFS volume that the kernel processes, typically requiring physical or removable media access or local write privileges. Because the flaw resides in kernel space, a successful exploitation could result in privilege escalation or denial of service.
OpenCVE Enrichment
Debian DSA