Impact
An off‑by‑one page overflow occurs in the Linux kernel's NTFS decompression routine, causing one byte to be written past the end of a destination page when decompressing a corrupted NTFS compressed data attribute. The out‑of‑bounds write can corrupt adjacent kernel memory and potentially lead to a kernel panic or other instability. According to the CVE report, the bug does not provide direct privilege escalation paths, but it represents a significant kernel memory corruption vulnerability.
Affected Systems
The flaw exists in the Linux kernel for all builds that contain the buggy ntfs_decompress implementation and have not yet applied the patch. No specific kernel version numbers are enumerated, so any kernel prior to the commit that introduced the fix is potentially vulnerable. The vulnerability resides in the kernel module that handles NTFS file systems.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for kernel memory corruption. The EPSS score of less than 1 % suggests that current exploitation attempts are rare or not publicly reported. The vulnerability is not listed in the CISA KEV catalog. Adversaries would need to supply a specially crafted compressed file on an NTFS volume that the vulnerable kernel mounts; this condition can be triggered locally or by any process that can write to the NTFS partition. The risk is therefore moderate in environments that expose the kernel to untrusted NTFS data, but the potential impact justifies prompt remediation.
OpenCVE Enrichment