Description
In the Linux kernel, the following vulnerability has been resolved:

ntfs: validate usa_ofs before preserving the update sequence number

When ntfs_mft_record_alloc() reuses a free mft record it reads the old
update sequence number straight from the on-disk record:

usn = *(__le16 *)((u8 *)m + le16_to_cpu(m->usa_ofs));

Here m points into the raw $MFT page-cache folio, which still holds
unvalidated, MST-protected bytes: the folio is read by a plain
iomap_read_folio() and neither post_read_mst_fixup() nor
ntfs_mft_record_check() has run on it (both work on private copies).
m->usa_ofs is therefore an untrusted u16, and a corrupted record can put
it past the end of the record so the two-byte read lands outside the
folio. Reading such a record while creating a file gives, under KASAN:

BUG: KASAN: use-after-free in ntfs_mft_record_alloc+...
Read of size 2 at addr ...
ntfs_mft_record_alloc -> __ntfs_create -> ntfs_create -> path_openat

Only preserve the old update sequence number when usa_ofs is even and in
range, mirroring the check ntfs_mft_record_check() already applies;
otherwise leave usn zero, which the existing restore below skips.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is in the Linux kernel's NTFS module. During MFT record allocation the kernel reads the update sequence number from an offset that comes directly from disk data without validating bounds. A corrupted NTFS volume can supply a value that points beyond the record’s end, causing the kernel to read memory outside the page cache. The errant read triggers a KASAN use‒after‒free, indicating that the kernel has accessed invalid memory. While this memory corruption does not directly grant code execution, it can lead to a kernel crash, a denial‒of‒service, or serve as a stepping stone toward privilege escalation if additional techniques are applied. The flaw is an out-of-bounds read combined with improper use of freed memory.

Affected Systems

All Linux kernel builds that include the ntfs module and predate commit 81684340963da2e898eabb8c1e274433d9375bc6 are vulnerable. This includes standard distributions that ship with a built-in NTFS driver or enable ntfs-3g. The problem exists regardless of distribution version as long as the kernel code predates the validation change.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalogue, indicating a low probability of widespread exploitation. Exploitation requires the attacker to control or fabricate an NTFS volume that the system mounts, so the attack surface is limited to environments where untrusted NTFS media can be accessed or a privileged process can mount such media. With this condition met, the attacker can trigger the out-of-bounds read and cause a kernel fault. The failure could crash the machine or expose a memory corruption that might be chained to privilege escalation, but no direct code execution vector is provided by the CVE itself.

Generated by OpenCVE AI on September 20, 2026 at 04:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes commit 81684340963da2e898eabb8c1e274433d9375bc6, which validates the usa_ofs offset before reading the update sequence number.
  • If a kernel update cannot be applied immediately, unload or disable the ntfs module so the kernel never loads the vulnerable code (e.g., using `modprobe -r ntfs` or configuring an install rule that prevents loading).
  • Restrict mounting of NTFS filesystems to trusted users or processes only; use SELinux, AppArmor, or filesystem permissions to ensure that only authorized entities can mount external NTFS volumes.
  • Monitor kernel logs for KASAN warnings or OOPS messages; a KASAN report indicates that the vulnerability was triggered.

Generated by OpenCVE AI on September 20, 2026 at 04:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ntfs: validate usa_ofs before preserving the update sequence number When ntfs_mft_record_alloc() reuses a free mft record it reads the old update sequence number straight from the on-disk record: usn = *(__le16 *)((u8 *)m + le16_to_cpu(m->usa_ofs)); Here m points into the raw $MFT page-cache folio, which still holds unvalidated, MST-protected bytes: the folio is read by a plain iomap_read_folio() and neither post_read_mst_fixup() nor ntfs_mft_record_check() has run on it (both work on private copies). m->usa_ofs is therefore an untrusted u16, and a corrupted record can put it past the end of the record so the two-byte read lands outside the folio. Reading such a record while creating a file gives, under KASAN: BUG: KASAN: use-after-free in ntfs_mft_record_alloc+... Read of size 2 at addr ... ntfs_mft_record_alloc -> __ntfs_create -> ntfs_create -> path_openat Only preserve the old update sequence number when usa_ofs is even and in range, mirroring the check ntfs_mft_record_check() already applies; otherwise leave usn zero, which the existing restore below skips.
Title ntfs: validate usa_ofs before preserving the update sequence number
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:22.705Z

Reserved: 2026-09-11T19:38:34.787Z

Link: CVE-2026-90117

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:03.857

Modified: 2026-09-17T17:17:03.857

Link: CVE-2026-90117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free