Impact
In the Linux kernel’s NTFS3 driver, an out‑of‑bounds read occurs when read_log_rec_buf() copies a log record into a buffer without ensuring that the offset stays within the page. The record length comes from the on‑disk restart area and is only validated for 8‑byte alignment, allowing the offset to exceed the page size. This underflow causes memcpy() to read beyond the intended buffer and spills adjacent slab memory into the replay buffer. A malicious user can mount a crafted NTFS image to trigger the error, leading to kernel memory disclosure and potential leakage of sensitive data.
Affected Systems
All Linux kernel versions that include the vulnerable NTFS3 driver before the patch referenced in the linked commits are affected. Distributions that compile or load NTFS3 support with those kernels are at risk, regardless of the specific kernel release number.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability. The EPSS score of less than 1% implies that exploitation is currently unlikely, though the defect is exploitable if an attacker can mount a crafted NTFS image. The description does not specify a privilege requirement, so the attack vector is likely local, potentially becoming remote if the system mounts NTFS images from untrusted network sources. The vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the risk of kernel memory disclosure merits prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA