Impact
The Linux kernel NTFS driver contained a flaw where the function that creates a list of attributes would write beyond the bounds of a pre‑allocated buffer. A maliciously crafted NTFS file system image can trigger this code path, causing an out‑of‑bounds write that can corrupt kernel memory and lead to arbitrary code execution. The bug is triggered by adding an attribute to a loop‑mounted NTFS image, a step that an attacker with the ability to mount files can perform.
Affected Systems
Any system running a Linux kernel that has not yet applied the patch containing the commits referenced in the advisory. This includes all distributions that ship with the vulnerable kernel version. No specific product version list is provided in the advisory, but all pre‑fix kernels are affected.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical level of severity. Although the EPSS score is less than 1%, the potential impact remains high because the flaw allows kernel memory corruption and can enable privileged code execution. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is mounting a crafted NTFS image and adding an attribute (for example with setxattr), which invokes the vulnerable code path and can lead to exploitation by an unprivileged user who can access the file system. The exploitation requires no special network access; it is a local privilege escalation to kernel level, making it a direct threat to systems that expose NTFS images to untrusted users.
OpenCVE Enrichment
Debian DLA
Debian DSA