Description
In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: validate ef->size covers the record's name and value

When an EA record has a non-zero ef->size, ntfs_read_ea() only checks
that the record fits in the remaining buffer (ea_size > bytes), not that
ef->size is large enough to hold the record's own name_len + 1 + elength.

A crafted image can pass validation with, e.g., ef->size = 24 but
elength = 0xffff. ntfs_get_ea() then trusts elength and copies it out of
the undersized record, reading past the kmalloc(info->size) allocation
and leaking heap memory to userspace via getxattr():

BUG: KASAN: slab-out-of-bounds in ntfs_get_ea (fs/ntfs3/xattr.c:302)
Read of size 65535 at addr ffff888100794550 by task exploit
__asan_memcpy (mm/kasan/shadow.c:105)
ntfs_get_ea (fs/ntfs3/xattr.c:302)
ntfs_getxattr (fs/ntfs3/xattr.c:848)
__vfs_getxattr (fs/xattr.c:441)
vfs_getxattr (fs/xattr.c:474)
do_getxattr (fs/xattr.c:800)
path_getxattrat (fs/xattr.c:868)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)

The buggy address is located 80 bytes inside of
allocated 84-byte region in cache kmalloc-96

Compute the size the record needs and require ef->size to cover it.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Heap Leak
Action: Apply Update
AI Analysis

Impact

The ntfs3 file‑system driver in the Linux kernel contains a flaw where the extended‑attribute (EA) record size is not fully validated. When ntfs_read_ea is called, it checks only that the record fits in the remaining buffer but does not ensure that the ea->size field is large enough to hold the EA name, a separator, and the value length. This oversight allows a crafted NTFS image to provide an elength that exceeds the allocated buffer, causing ntfs_get_ea to read past the end of the region and copy kernel heap memory into userspace via the getxattr system call. The result is a buffer over‑read leading to an information‑disclosure vulnerability that can leak sensitive kernel data.

Affected Systems

Affected systems are Linux kernel implementations that include the ntfs3 driver. The vendor is Linux and the product is the Linux kernel. No specific release numbers are listed in the CNA data, indicating that any kernel version prior to the patch is potentially vulnerable.

Risk and Exploitability

The CVSS score of 9.1 marks this flaw as high‑severity, but the EPSS score of <1% suggests that exploitation in the wild is unlikely at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access to a crafted NTFS volume, such as through mounting an externally supplied image. The attack read‑only kernel heap data, leading to potential exposure of confidential information but not allowing code execution or privilege escalation.

Generated by OpenCVE AI on September 20, 2026 at 04:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the ntfs3 EA size verification patch.
  • If the kernel cannot be updated immediately, disable the ntfs3 module until the patch is available and prevent its automatic loading.
  • Avoid mounting NTFS filesystems from untrusted or externally supplied media until the vulnerability is addressed.

Generated by OpenCVE AI on September 20, 2026 at 04:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-20
CWE-200

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-20
CWE-200

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Wed, 16 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's name and value When an EA record has a non-zero ef->size, ntfs_read_ea() only checks that the record fits in the remaining buffer (ea_size > bytes), not that ef->size is large enough to hold the record's own name_len + 1 + elength. A crafted image can pass validation with, e.g., ef->size = 24 but elength = 0xffff. ntfs_get_ea() then trusts elength and copies it out of the undersized record, reading past the kmalloc(info->size) allocation and leaking heap memory to userspace via getxattr(): BUG: KASAN: slab-out-of-bounds in ntfs_get_ea (fs/ntfs3/xattr.c:302) Read of size 65535 at addr ffff888100794550 by task exploit __asan_memcpy (mm/kasan/shadow.c:105) ntfs_get_ea (fs/ntfs3/xattr.c:302) ntfs_getxattr (fs/ntfs3/xattr.c:848) __vfs_getxattr (fs/xattr.c:441) vfs_getxattr (fs/xattr.c:474) do_getxattr (fs/xattr.c:800) path_getxattrat (fs/xattr.c:868) do_syscall_64 (arch/x86/entry/syscall_64.c:94) The buggy address is located 80 bytes inside of allocated 84-byte region in cache kmalloc-96 Compute the size the record needs and require ef->size to cover it.
Title fs/ntfs3: validate ef->size covers the record's name and value
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:38:31.147Z

Reserved: 2026-09-11T19:38:34.765Z

Link: CVE-2026-89779

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T09:17:08.387

Modified: 2026-09-16T15:18:07.320

Link: CVE-2026-89779

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:45:17Z

Weaknesses