Impact
The flaw in the Linux ntfs3 driver is a weakness described by CWE-908 (Information Exposure through Improper Handling of Uninitialized Data). When an LZNT $DATA frame is partially decompressed, the code trusts the decompress_lznt() return value but ignores the remaining part of the frame. The uninitialized tail preserves old kernel page contents and is not zeroed, causing the kernel to return these garbage pages to userspace via a normal read system call, exposing kernel pointers and disabling KASLR. The vulnerability does not give arbitrary code execution but provides a valuable foothold for further running versions prior to the inclusion of the patch that zeroes the decompressed frame tail are affected. Any distribution that ships with the unpatched kernel or that has not yet incorporated the upstream commit provides attackers a window for exploitation, including mainstream mainline kernels and backported releases lacking the fix. The vulnerability carries a CVSS score of 7.5, indicating a high severity, but its EPSS score is below 1 %, implying a low likelihood of exploitation at this time. The issue is not catalogued in the a malicious NTFS file that the system will read—either by mounting an NTFS volume or by an application accessing the file—so the attack vector is local, with a crafted file as the trigger. Attackers would need sufficient privileges to read the file but no additional kernel interaction. The low EPSS suggests that current exploit usage is minimal, yet the information leakage can be combined with other weaknesses to bypass KASLR or mount a privilege escalation scenario.
Affected Systems
All Linux kernels running versions prior to the inclusion of the patch that zeroes the decompressed frame tail are affected. Any distribution that ships with the unpatched kernel or that has not yet incorporated the upstream commit provides attackers a window for exploitation, including mainstream mainline kernels and backported releases lacking the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating a high severity, but its EPSS score is below 1 %, implying a low likelihood of exploitation at this time. The issue is not catalogued in the CISA KEFS file that the system will read—either by mounting an NTFS volume or by an application accessing the file—so the attack vector is local, with a crafted file as the trigger. Attackers would need sufficient privileges to read the file but no additional kernel interaction. The low EPSS suggests that current exploit usage is minimal, yet the information leakage can be combined with other weaknesses to bypass KASLR or mount a privilege escalation scenario.
OpenCVE Enrichment
Debian DSA