Impact
The ntfs3 driver contains a flaw where the restart table count, stored as a 16‑bit value, is derived from a 32‑bit calculation. A crafted NTFS image can cause the calculation to exceed the 16‑bit maximum, resulting in a truncated count and an allocation that is smaller than required. The subsequent write occurs beyond the allocated buffer, triggering an out‑of‑bounds write and a use‑after‑free. This can corrupt kernel memory, potentially affecting kernel integrity.
Affected Systems
All Linux kernel builds that include the ntfs3 filesystem driver are affected. The vulnerability is present in the ntfs3 module code that handles NTFS log replay during mount time, and any kernel that mounts a malicious NTFS volume can be impacted.
Risk and Exploitability
The flaw requires an attacker to mount a specially crafted NTFS volume, so local mount operations are the primary attack vector. The CVSS score of 8.4 indicates high severity, while the EPSS score of <1% and the absence from CISA KEV suggest exploitation is currently rare. If exploited, the kernel memory corruption could lead to elevated privileges, as the attacker can corrupt critical kernel data structures. The nature of the flaw allows the attacker to influence kernel execution flow indirectly, but the exact consequences depend on the specific corruption achieved.
OpenCVE Enrichment
Debian DLA
Debian DSA