Description
In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list()

ni_create_attr_list() allocates a fixed buffer of al_aligned(record_size)
(== record_size) bytes and then walks every attribute of the primary MFT
record, writing one ATTR_LIST_ENTRY per attribute and advancing the cursor
by le_size(name_len), with no check against the end of the buffer; the
total size is only computed after the loop.

A minimum-size resident attribute occupies SIZEOF_RESIDENT (0x18 = 24)
bytes on disk, but an unnamed attribute expands to le_size(0) (0x20 = 32)
bytes in the list. Because the number of attributes in a record is not
bounded (mi_enum_attr() accepts arbitrarily many equal-type, nameless
minimum-size attributes), a crafted record packed with such attributes
produces a list larger than record_size and overflows the heap buffer.

This is reachable from a crafted, loop-mounted NTFS image: opening the file
and adding an attribute (e.g. via setxattr) drives ntfs_set_ea() ->
ni_insert_resident() -> ni_insert_attr() -> ni_ins_attr_ext() ->
ni_create_attr_list().

BUG: KASAN: slab-out-of-bounds in ni_create_attr_list+0xc48/0x1058
Write of size 4 at addr ffff000008984c00 by task setfattr/345
ni_create_attr_list+0xc48/0x1058
ni_ins_attr_ext+0x510/0x7c0
ni_insert_attr+0x3f8/0x70c
ni_insert_resident+0xc8/0x3b0
ntfs_set_ea+0x66c/0xd28
ntfs_setxattr+0x4d8/0x5b0
__arm64_sys_setxattr+0xa4/0x124
Allocated by task 345:
ni_create_attr_list+0x188/0x1058
The buggy address belongs to the cache kmalloc-1k of size 1024
(the write lands at object+1024).

Size the buffer from the actual attributes instead of assuming a single
record_size is always enough.
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel out‑of‑bounds write potentially enabling remote code execution
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel NTFS driver contained a flaw where the function that creates a list of attributes would write beyond the bounds of a pre‑allocated buffer. A maliciously crafted NTFS file system image can trigger this code path, causing an out‑of‑bounds write that can corrupt kernel memory and lead to arbitrary code execution. The bug is triggered by adding an attribute to a loop‑mounted NTFS image, a step that an attacker with the ability to mount files can perform.

Affected Systems

Any system running a Linux kernel that has not yet applied the patch containing the commits referenced in the advisory. This includes all distributions that ship with the vulnerable kernel version. No specific product version list is provided in the advisory, but all pre‑fix kernels are affected.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical level of severity. Although the EPSS score is less than 1%, the potential impact remains high because the flaw allows kernel memory corruption and can enable privileged code execution. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is mounting a crafted NTFS image and adding an attribute (for example with setxattr), which invokes the vulnerable code path and can lead to exploitation by an unprivileged user who can access the file system. The exploitation requires no special network access; it is a local privilege escalation to kernel level, making it a direct threat to systems that expose NTFS images to untrusted users.

Generated by OpenCVE AI on September 18, 2026 at 06:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel that includes the commit(s) fixing the bug (check distribution's security advisory for the specific patch reference).
  • Restrict access to NTFS loop mounts by limiting the ability to mount loop devices to trusted users or groups; avoid giving untrusted users permission to mount or write to NTFS images.
  • Monitor system logs and kernel crash reports (e.g., dmesg, /var/log/kern.log) for signs of slab‑out‑of‑bounds or KASAN messages; if detected, apply the patch or roll back immediately.

Generated by OpenCVE AI on September 18, 2026 at 06:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() ni_create_attr_list() allocates a fixed buffer of al_aligned(record_size) (== record_size) bytes and then walks every attribute of the primary MFT record, writing one ATTR_LIST_ENTRY per attribute and advancing the cursor by le_size(name_len), with no check against the end of the buffer; the total size is only computed after the loop. A minimum-size resident attribute occupies SIZEOF_RESIDENT (0x18 = 24) bytes on disk, but an unnamed attribute expands to le_size(0) (0x20 = 32) bytes in the list. Because the number of attributes in a record is not bounded (mi_enum_attr() accepts arbitrarily many equal-type, nameless minimum-size attributes), a crafted record packed with such attributes produces a list larger than record_size and overflows the heap buffer. This is reachable from a crafted, loop-mounted NTFS image: opening the file and adding an attribute (e.g. via setxattr) drives ntfs_set_ea() -> ni_insert_resident() -> ni_insert_attr() -> ni_ins_attr_ext() -> ni_create_attr_list(). BUG: KASAN: slab-out-of-bounds in ni_create_attr_list+0xc48/0x1058 Write of size 4 at addr ffff000008984c00 by task setfattr/345 ni_create_attr_list+0xc48/0x1058 ni_ins_attr_ext+0x510/0x7c0 ni_insert_attr+0x3f8/0x70c ni_insert_resident+0xc8/0x3b0 ntfs_set_ea+0x66c/0xd28 ntfs_setxattr+0x4d8/0x5b0 __arm64_sys_setxattr+0xa4/0x124 Allocated by task 345: ni_create_attr_list+0x188/0x1058 The buggy address belongs to the cache kmalloc-1k of size 1024 (the write lands at object+1024). Size the buffer from the actual attributes instead of assuming a single record_size is always enough.
Title fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:42:04.456Z

Reserved: 2026-09-11T19:38:34.783Z

Link: CVE-2026-90048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:18.140

Modified: 2026-09-28T23:10:00.143

Link: CVE-2026-90048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:30:05Z

Weaknesses

No weakness.