Description
In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: reject restart table growth beyond U16_MAX entries

During $LogFile replay, log_replay() indexes the transaction table by the
transact_id taken from the log record header. check_log_rec() only
verifies that transact_id is non-zero and properly aligned, not its
magnitude, so a crafted image can request an arbitrarily large index.

alloc_rsttbl_from_idx() grows the table to cover that index via
extend_rsttbl(), which passes the new entry count to init_rsttbl():

rt = init_rsttbl(esize, used + add);

used + add is computed as u32 but init_rsttbl() takes a u16, and the
count is stored in struct RESTART_TABLE as a __le16. When used + add
exceeds U16_MAX it is truncated, init_rsttbl() allocates a table far
smaller than the index requires, and alloc_rsttbl_from_idx() then
dereferences and writes at the original, untruncated offset -- an
out-of-bounds access past the allocation, reachable by mounting a
crafted NTFS image.

BUG: KASAN: use-after-free in alloc_rsttbl_from_idx (fs/ntfs3/fslog.c:950)
Read of size 4 at addr ffff8880327ffff8 by task exploit
alloc_rsttbl_from_idx (fs/ntfs3/fslog.c:950)
log_replay (fs/ntfs3/fslog.c:4562)
ntfs_loadlog_and_replay (fs/ntfs3/fsntfs.c:324)
ntfs_fill_super (fs/ntfs3/super.c:1393)
get_tree_bdev_flags
vfs_get_tree
path_mount
__x64_sys_mount

A restart table is limited to U16_MAX entries by its __le16 count, so a
larger growth request is invalid input. Reject it in extend_rsttbl();
all callers already handle a NULL return.
Published: 2026-09-16
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption potential
Action: Patch
AI Analysis

Impact

The ntfs3 driver contains a flaw where the restart table count, stored as a 16‑bit value, is derived from a 32‑bit calculation. A crafted NTFS image can cause the calculation to exceed the 16‑bit maximum, resulting in a truncated count and an allocation that is smaller than required. The subsequent write occurs beyond the allocated buffer, triggering an out‑of‑bounds write and a use‑after‑free. This can corrupt kernel memory, potentially affecting kernel integrity.

Affected Systems

All Linux kernel builds that include the ntfs3 filesystem driver are affected. The vulnerability is present in the ntfs3 module code that handles NTFS log replay during mount time, and any kernel that mounts a malicious NTFS volume can be impacted.

Risk and Exploitability

The flaw requires an attacker to mount a specially crafted NTFS volume, so local mount operations are the primary attack vector. The CVSS score of 8.4 indicates high severity, while the EPSS score of <1% and the absence from CISA KEV suggest exploitation is currently rare. If exploited, the kernel memory corruption could lead to elevated privileges, as the attacker can corrupt critical kernel data structures. The nature of the flaw allows the attacker to influence kernel execution flow indirectly, but the exact consequences depend on the specific corruption achieved.

Generated by OpenCVE AI on September 20, 2026 at 04:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that incorporates the fixed ntfs3 commit, which correctly rejects restart table growth beyond the 16‑bit limit.
  • If an updated kernel is unavailable, mount NTFS volumes as read‑only or disable the ntfs3 module entirely until a patch is applied.
  • Monitor kernel logs for KASAN messages indicating a buffer overflow on "alloc_rsttbl_from_idx" and promptly apply any released patches if detected.

Generated by OpenCVE AI on September 20, 2026 at 04:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 18 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-787

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-787
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject restart table growth beyond U16_MAX entries During $LogFile replay, log_replay() indexes the transaction table by the transact_id taken from the log record header. check_log_rec() only verifies that transact_id is non-zero and properly aligned, not its magnitude, so a crafted image can request an arbitrarily large index. alloc_rsttbl_from_idx() grows the table to cover that index via extend_rsttbl(), which passes the new entry count to init_rsttbl(): rt = init_rsttbl(esize, used + add); used + add is computed as u32 but init_rsttbl() takes a u16, and the count is stored in struct RESTART_TABLE as a __le16. When used + add exceeds U16_MAX it is truncated, init_rsttbl() allocates a table far smaller than the index requires, and alloc_rsttbl_from_idx() then dereferences and writes at the original, untruncated offset -- an out-of-bounds access past the allocation, reachable by mounting a crafted NTFS image. BUG: KASAN: use-after-free in alloc_rsttbl_from_idx (fs/ntfs3/fslog.c:950) Read of size 4 at addr ffff8880327ffff8 by task exploit alloc_rsttbl_from_idx (fs/ntfs3/fslog.c:950) log_replay (fs/ntfs3/fslog.c:4562) ntfs_loadlog_and_replay (fs/ntfs3/fsntfs.c:324) ntfs_fill_super (fs/ntfs3/super.c:1393) get_tree_bdev_flags vfs_get_tree path_mount __x64_sys_mount A restart table is limited to U16_MAX entries by its __le16 count, so a larger growth request is invalid input. Reject it in extend_rsttbl(); all callers already handle a NULL return.
Title fs/ntfs3: reject restart table growth beyond U16_MAX entries
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:38:33.748Z

Reserved: 2026-09-11T19:38:34.765Z

Link: CVE-2026-89782

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T09:17:08.800

Modified: 2026-09-16T15:18:08.577

Link: CVE-2026-89782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:45:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer