Description
In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: fix out-of-bounds read in read_log_rec_buf()

read_log_rec_buf() copies a log record into a caller buffer starting at

u32 off = lsn_to_page_off(log, lsn) + log->record_header_len;

log->record_header_len (and log->data_off, used for the following pages)
comes verbatim from the on-disk restart area and is only checked for
8-byte alignment in is_rst_area_valid(), so off can exceed
log->page_size. "tail = log->page_size - off" then underflows and
memcpy() reads past the page_size-sized buffer returned by
read_log_page(), spilling adjacent slab memory into the replay buffer.

This is reachable by mounting a crafted NTFS image:

BUG: KASAN: slab-out-of-bounds in read_log_rec_buf+0x216/0x580
Read of size 64 at addr ffff88800a877ff8 by task exploit/127
read_log_rec_buf fs/ntfs3/fslog.c:2299
log_replay fs/ntfs3/fslog.c:4216
ntfs_loadlog_and_replay fs/ntfs3/fsntfs.c:324
ntfs_fill_super fs/ntfs3/super.c:1392
get_tree_bdev_flags fs/super.c:1694
__x64_sys_mount fs/namespace.c:4360
The buggy address is located 4088 bytes to the right of
the 4096-byte region [ffff88800a876000, ffff88800a877000)

Reject an in-page offset outside the current page before the copy.

[almaz.alexandrovich@paragon-software.com: replaced the >= sign with >]
Published: 2026-09-16
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure
Action: Apply patch
AI Analysis

Impact

In the Linux kernel’s NTFS3 driver, an out‑of‑bounds read occurs when read_log_rec_buf() copies a log record into a buffer without ensuring that the offset stays within the page. The record length comes from the on‑disk restart area and is only validated for 8‑byte alignment, allowing the offset to exceed the page size. This underflow causes memcpy() to read beyond the intended buffer and spills adjacent slab memory into the replay buffer. A malicious user can mount a crafted NTFS image to trigger the error, leading to kernel memory disclosure and potential leakage of sensitive data.

Affected Systems

All Linux kernel versions that include the vulnerable NTFS3 driver before the patch referenced in the linked commits are affected. Distributions that compile or load NTFS3 support with those kernels are at risk, regardless of the specific kernel release number.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity vulnerability. The EPSS score of less than 1% implies that exploitation is currently unlikely, though the defect is exploitable if an attacker can mount a crafted NTFS image. The description does not specify a privilege requirement, so the attack vector is likely local, potentially becoming remote if the system mounts NTFS images from untrusted network sources. The vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the risk of kernel memory disclosure merits prompt remediation.

Generated by OpenCVE AI on September 20, 2026 at 05:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch associated with the commits linked in the advisory.
  • Upgrade the kernel to a version that includes the fix if an update is available.
  • If an upgrade is not yet possible, disable NTFS3 support in the kernel configuration (CONFIG_NTFS3 = n).

Generated by OpenCVE AI on September 20, 2026 at 05:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-20

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-20

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() read_log_rec_buf() copies a log record into a caller buffer starting at u32 off = lsn_to_page_off(log, lsn) + log->record_header_len; log->record_header_len (and log->data_off, used for the following pages) comes verbatim from the on-disk restart area and is only checked for 8-byte alignment in is_rst_area_valid(), so off can exceed log->page_size. "tail = log->page_size - off" then underflows and memcpy() reads past the page_size-sized buffer returned by read_log_page(), spilling adjacent slab memory into the replay buffer. This is reachable by mounting a crafted NTFS image: BUG: KASAN: slab-out-of-bounds in read_log_rec_buf+0x216/0x580 Read of size 64 at addr ffff88800a877ff8 by task exploit/127 read_log_rec_buf fs/ntfs3/fslog.c:2299 log_replay fs/ntfs3/fslog.c:4216 ntfs_loadlog_and_replay fs/ntfs3/fsntfs.c:324 ntfs_fill_super fs/ntfs3/super.c:1392 get_tree_bdev_flags fs/super.c:1694 __x64_sys_mount fs/namespace.c:4360 The buggy address is located 4088 bytes to the right of the 4096-byte region [ffff88800a876000, ffff88800a877000) Reject an in-page offset outside the current page before the copy. [almaz.alexandrovich@paragon-software.com: replaced the >= sign with >]
Title fs/ntfs3: fix out-of-bounds read in read_log_rec_buf()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:38:32.420Z

Reserved: 2026-09-11T19:38:34.765Z

Link: CVE-2026-89781

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T09:17:08.667

Modified: 2026-09-16T15:18:07.470

Link: CVE-2026-89781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:30:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor