Description
In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: validate dirty page table on log replay

Each DIR_PAGE_ENTRY ends in a page_lcns[] array whose length is the on-disk
lcns_follow field. check_rstbl() validates the table bookkeeping but never
checks that this array fits in the entry, so a crafted lcns_follow lets the
v0->v1 conversion memmove and later replay passes run off the entry.

Add check_dp_table() to reject, right after check_rstbl(), any entry larger
than its size claims via struct_size() (the same expression used to allocate
these entries, so the check is overflow-safe by construction). All consumers
can then trust lcns_follow as the real capacity. This covers every
page_lcns[] access whose index is bounded by the entry itself (the
conversion memmove, the HotFix store via find_dp(), and the self-bounded
scan loops). Accesses whose index comes from the log record need a separate
bound and are handled in a follow-up patch.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption via out-of-bounds write
Action: Patch Immediately
AI Analysis

Impact

The Linux kernel’s ntfs3 filesystem module contains a flaw in the log replay process where the validation of a DIR_PAGE_ENTRY’s page_lcns[] array does not check that the length specified in the on‑disk lcns_follow field fits within the actual entry size. An attacker who can write a crafted lcns_follow value can trigger the libc memmove during a v0->v1 conversion or later replay to walk outside the bounds of the entry, causing an out‑of‑bounds write that corrupts kernel memory. This memory corruption can lead to arbitrary code execution, privilege escalation, or denial of service at the system level.

Affected Systems

This vulnerability resides in the core ntfs3 module of the Linux kernel, so any distribution that ships with the kernel and mounts NTFS3 filesystems is potentially affected. Because specific kernel release numbers are not listed, all unpatched kernels that include ntfs3 are at risk. The flaw is not tied to a particular distro release, meaning any system3 and accesses an NTFS3 filesystem can be impacted.

Risk and Exploitability

The CVSS score of 7.8 reflects a moderately high severity that can compromise confidentiality, integrity, and availability. The EPSS score is below 1%, indicating a low yet non‑zero likelihood of exploitation. The likelihood of exploitation is low and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is local; an adversary who can write to an NTFS3 volume can fabricate a malicious log entry that triggers the replay and the out‑of‑bounds write. Successful exploitation would corrupt kernel memory, potentially leading to arbitrary code execution or a system crash, but the need to write to a local file system reduces the likelihood of widespread exploitation.

Generated by OpenCVE AI on September 15, 2026 at 21:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the check_dp_table patch to eliminate the overflow.
  • While waiting for a kernel upgrade, unmount or block NTFS3 filesystems to prevent log replay attempts.
  • If NTFS3 support is not required, disable the ntfs3 kernel module entirely to remove the vulnerable code path.

Generated by OpenCVE AI on September 15, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate dirty page table on log replay Each DIR_PAGE_ENTRY ends in a page_lcns[] array whose length is the on-disk lcns_follow field. check_rstbl() validates the table bookkeeping but never checks that this array fits in the entry, so a crafted lcns_follow lets the v0->v1 conversion memmove and later replay passes run off the entry. Add check_dp_table() to reject, right after check_rstbl(), any entry larger than its size claims via struct_size() (the same expression used to allocate these entries, so the check is overflow-safe by construction). All consumers can then trust lcns_follow as the real capacity. This covers every page_lcns[] access whose index is bounded by the entry itself (the conversion memmove, the HotFix store via find_dp(), and the self-bounded scan loops). Accesses whose index comes from the log record need a separate bound and are handled in a follow-up patch.
Title fs/ntfs3: validate dirty page table on log replay
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:33.173Z

Reserved: 2026-09-11T19:38:34.735Z

Link: CVE-2026-89617

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:46.917

Modified: 2026-09-14T13:19:15.707

Link: CVE-2026-89617

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:45:16Z

Links: CVE-2026-89617 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses