Impact
The Linux kernel’s ntfs3 filesystem module contains a flaw in the log replay process where the validation of a DIR_PAGE_ENTRY’s page_lcns[] array does not check that the length specified in the on‑disk lcns_follow field fits within the actual entry size. An attacker who can write a crafted lcns_follow value can trigger the libc memmove during a v0->v1 conversion or later replay to walk outside the bounds of the entry, causing an out‑of‑bounds write that corrupts kernel memory. This memory corruption can lead to arbitrary code execution, privilege escalation, or denial of service at the system level.
Affected Systems
This vulnerability resides in the core ntfs3 module of the Linux kernel, so any distribution that ships with the kernel and mounts NTFS3 filesystems is potentially affected. Because specific kernel release numbers are not listed, all unpatched kernels that include ntfs3 are at risk. The flaw is not tied to a particular distro release, meaning any system3 and accesses an NTFS3 filesystem can be impacted.
Risk and Exploitability
The CVSS score of 7.8 reflects a moderately high severity that can compromise confidentiality, integrity, and availability. The EPSS score is below 1%, indicating a low yet non‑zero likelihood of exploitation. The likelihood of exploitation is low and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is local; an adversary who can write to an NTFS3 volume can fabricate a malicious log entry that triggers the replay and the out‑of‑bounds write. Successful exploitation would corrupt kernel memory, potentially leading to arbitrary code execution or a system crash, but the need to write to a local file system reduces the likelihood of widespread exploitation.
OpenCVE Enrichment
Debian DSA