Description
In the Linux kernel, the following vulnerability has been resolved:

ntfs: fix off-by-one page overflow in ntfs_decompress()

The per-token range check in ntfs_decompress() uses

if (cb >= cb_sb_end || dp_addr > dp_sb_end)
break;

so dp_addr == dp_sb_end falls through to the symbol copy
`*dp_addr++ = *cb++`, writing one byte past the destination page. Since
NTFS_SB_SIZE == PAGE_SIZE the destination is a single page, so the byte
lands in the adjacent page, and *dest_ofs is left one past the sub-block
end (the later `*dest_ofs &= ~PAGE_MASK` then yields 1, not 0, so the page
is never finalized and later sub-blocks keep writing further past it). A
corrupted compressed $DATA attribute thus produces a bounded run of
out-of-bounds writes when the file is read.

Break as soon as dp_addr reaches dp_sb_end; a full sub-block still
completes, as its final copy advances dp_addr to exactly dp_sb_end.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Apply patch
AI Analysis

Impact

An off‑by‑one page overflow occurs in the Linux kernel's NTFS decompression routine, causing one byte to be written past the end of a destination page when decompressing a corrupted NTFS compressed data attribute. The out‑of‑bounds write can corrupt adjacent kernel memory and potentially lead to a kernel panic or other instability. According to the CVE report, the bug does not provide direct privilege escalation paths, but it represents a significant kernel memory corruption vulnerability.

Affected Systems

The flaw exists in the Linux kernel for all builds that contain the buggy ntfs_decompress implementation and have not yet applied the patch. No specific kernel version numbers are enumerated, so any kernel prior to the commit that introduced the fix is potentially vulnerable. The vulnerability resides in the kernel module that handles NTFS file systems.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity for kernel memory corruption. The EPSS score of less than 1 % suggests that current exploitation attempts are rare or not publicly reported. The vulnerability is not listed in the CISA KEV catalog. Adversaries would need to supply a specially crafted compressed file on an NTFS volume that the vulnerable kernel mounts; this condition can be triggered locally or by any process that can write to the NTFS partition. The risk is therefore moderate in environments that expose the kernel to untrusted NTFS data, but the potential impact justifies prompt remediation.

Generated by OpenCVE AI on September 20, 2026 at 05:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the ntfs_decompress fix.
  • If an update is unavailable, unload or disable the ntfs module to avoid processing NTFS volumes.
  • Limit write access to NTFS partitions to trusted users or processes to prevent the creation of malicious compressed files.

Generated by OpenCVE AI on September 20, 2026 at 05:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one page overflow in ntfs_decompress() The per-token range check in ntfs_decompress() uses if (cb >= cb_sb_end || dp_addr > dp_sb_end) break; so dp_addr == dp_sb_end falls through to the symbol copy `*dp_addr++ = *cb++`, writing one byte past the destination page. Since NTFS_SB_SIZE == PAGE_SIZE the destination is a single page, so the byte lands in the adjacent page, and *dest_ofs is left one past the sub-block end (the later `*dest_ofs &= ~PAGE_MASK` then yields 1, not 0, so the page is never finalized and later sub-blocks keep writing further past it). A corrupted compressed $DATA attribute thus produces a bounded run of out-of-bounds writes when the file is read. Break as soon as dp_addr reaches dp_sb_end; a full sub-block still completes, as its final copy advances dp_addr to exactly dp_sb_end.
Title ntfs: fix off-by-one page overflow in ntfs_decompress()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:07.562Z

Reserved: 2026-09-11T19:38:34.787Z

Link: CVE-2026-90118

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:03.963

Modified: 2026-09-18T18:17:42.627

Link: CVE-2026-90118

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:00:14Z

Weaknesses

No weakness.