Impact
The vulnerability is in the Linux kernel's NTFS module. During MFT record allocation the kernel reads the update sequence number from an offset that comes directly from disk data without validating bounds. A corrupted NTFS volume can supply a value that points beyond the record’s end, causing the kernel to read memory outside the page cache. The errant read triggers a KASAN use‒after‒free, indicating that the kernel has accessed invalid memory. While this memory corruption does not directly grant code execution, it can lead to a kernel crash, a denial‒of‒service, or serve as a stepping stone toward privilege escalation if additional techniques are applied. The flaw is an out-of-bounds read combined with improper use of freed memory.
Affected Systems
All Linux kernel builds that include the ntfs module and predate commit 81684340963da2e898eabb8c1e274433d9375bc6 are vulnerable. This includes standard distributions that ship with a built-in NTFS driver or enable ntfs-3g. The problem exists regardless of distribution version as long as the kernel code predates the validation change.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalogue, indicating a low probability of widespread exploitation. Exploitation requires the attacker to control or fabricate an NTFS volume that the system mounts, so the attack surface is limited to environments where untrusted NTFS media can be accessed or a privileged process can mount such media. With this condition met, the attacker can trigger the out-of-bounds read and cause a kernel fault. The failure could crash the machine or expose a memory corruption that might be chained to privilege escalation, but no direct code execution vector is provided by the CVE itself.
OpenCVE Enrichment