Impact
The ntfs3 file‑system driver in the Linux kernel contains a flaw where the extended‑attribute (EA) record size is not fully validated. When ntfs_read_ea is called, it checks only that the record fits in the remaining buffer but does not ensure that the ea->size field is large enough to hold the EA name, a separator, and the value length. This oversight allows a crafted NTFS image to provide an elength that exceeds the allocated buffer, causing ntfs_get_ea to read past the end of the region and copy kernel heap memory into userspace via the getxattr system call. The result is a buffer over‑read leading to an information‑disclosure vulnerability that can leak sensitive kernel data.
Affected Systems
Affected systems are Linux kernel implementations that include the ntfs3 driver. The vendor is Linux and the product is the Linux kernel. No specific release numbers are listed in the CNA data, indicating that any kernel version prior to the patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.1 marks this flaw as high‑severity, but the EPSS score of <1% suggests that exploitation in the wild is unlikely at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access to a crafted NTFS volume, such as through mounting an externally supplied image. The attack read‑only kernel heap data, leading to potential exposure of confidential information but not allowing code execution or privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA