Description
In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()

ni_read_frame() decompresses an LZNT $DATA frame into the vmapped target
pages and then trusts decompress_lznt()'s return value:

unc_size = decompress_lznt(frame_ondisk, ondisk_size, frame_mem,
frame_size);
if ((ssize_t)unc_size < 0) err = unc_size;
else if (!unc_size || unc_size > frame_size) err = -EINVAL;

decompress_lznt() stops as soon as the compressed stream is exhausted
(e.g. a zero chunk header) and returns the number of bytes it actually
wrote, which may be far less than frame_size. The bytes between unc_size
and frame_size are never written. The only memset() that follows zeroes
the region beyond i_valid; when the frame lies entirely within the file's
valid size that memset() does not run, so the gap retains whatever was in
the just-vmapped pages. All pages are then marked uptodate and returned
to userspace, disclosing uninitialized (recently-freed) kernel page
memory. A crafted compressed file whose stream decompresses to only a few
bytes leaks the remainder of every frame on a plain read(2), which is
enough to recover kernel pointers and defeat KASLR.

Zero the [unc_size, frame_size) tail immediately after a successful LZNT
decompress so the remainder reads back as zero.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure through kernel memory leakage
Action: Apply kernel patch
AI Analysis

Impact

The flaw in the Linux ntfs3 driver is a weakness described by CWE-908 (Information Exposure through Improper Handling of Uninitialized Data). When an LZNT $DATA frame is partially decompressed, the code trusts the decompress_lznt() return value but ignores the remaining part of the frame. The uninitialized tail preserves old kernel page contents and is not zeroed, causing the kernel to return these garbage pages to userspace via a normal read system call, exposing kernel pointers and disabling KASLR. The vulnerability does not give arbitrary code execution but provides a valuable foothold for further running versions prior to the inclusion of the patch that zeroes the decompressed frame tail are affected. Any distribution that ships with the unpatched kernel or that has not yet incorporated the upstream commit provides attackers a window for exploitation, including mainstream mainline kernels and backported releases lacking the fix. The vulnerability carries a CVSS score of 7.5, indicating a high severity, but its EPSS score is below 1 %, implying a low likelihood of exploitation at this time. The issue is not catalogued in the a malicious NTFS file that the system will read—either by mounting an NTFS volume or by an application accessing the file—so the attack vector is local, with a crafted file as the trigger. Attackers would need sufficient privileges to read the file but no additional kernel interaction. The low EPSS suggests that current exploit usage is minimal, yet the information leakage can be combined with other weaknesses to bypass KASLR or mount a privilege escalation scenario.

Affected Systems

All Linux kernels running versions prior to the inclusion of the patch that zeroes the decompressed frame tail are affected. Any distribution that ships with the unpatched kernel or that has not yet incorporated the upstream commit provides attackers a window for exploitation, including mainstream mainline kernels and backported releases lacking the fix.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating a high severity, but its EPSS score is below 1 %, implying a low likelihood of exploitation at this time. The issue is not catalogued in the CISA KEFS file that the system will read—either by mounting an NTFS volume or by an application accessing the file—so the attack vector is local, with a crafted file as the trigger. Attackers would need sufficient privileges to read the file but no additional kernel interaction. The low EPSS suggests that current exploit usage is minimal, yet the information leakage can be combined with other weaknesses to bypass KASLR or mount a privilege escalation scenario.

Generated by OpenCVE AI on September 15, 2026 at 21:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the ntfs3 patch
  • Mount any NTFS partitions in read‑only mode until the kernel is updated to prevent uninitialized data exposure
  • Unload or disable the ntfs3 kernel module if NTFS support is not required

Generated by OpenCVE AI on September 15, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Sat, 12 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-254

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-908
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Sat, 12 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-254

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() ni_read_frame() decompresses an LZNT $DATA frame into the vmapped target pages and then trusts decompress_lznt()'s return value: unc_size = decompress_lznt(frame_ondisk, ondisk_size, frame_mem, frame_size); if ((ssize_t)unc_size < 0) err = unc_size; else if (!unc_size || unc_size > frame_size) err = -EINVAL; decompress_lznt() stops as soon as the compressed stream is exhausted (e.g. a zero chunk header) and returns the number of bytes it actually wrote, which may be far less than frame_size. The bytes between unc_size and frame_size are never written. The only memset() that follows zeroes the region beyond i_valid; when the frame lies entirely within the file's valid size that memset() does not run, so the gap retains whatever was in the just-vmapped pages. All pages are then marked uptodate and returned to userspace, disclosing uninitialized (recently-freed) kernel page memory. A crafted compressed file whose stream decompresses to only a few bytes leaks the remainder of every frame on a plain read(2), which is enough to recover kernel pointers and defeat KASLR. Zero the [unc_size, frame_size) tail immediately after a successful LZNT decompress so the remainder reads back as zero.
Title fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:32.105Z

Reserved: 2026-09-11T19:38:34.735Z

Link: CVE-2026-89616

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:46.783

Modified: 2026-09-14T13:19:15.547

Link: CVE-2026-89616

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:16Z

Links: CVE-2026-89616 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource