Impact
The Linux kernel’s NTFS driver contains a race condition where reading resident inode map data occurs without holding the mrec_lock, while concurrent write operations such as ntfs_attr_record_resize can relocate the same MFT record under the lock. This allows a reader to observe torn attribute length and offset fields, as demonstrated by KCSAN reports during mmap fault handling versus link/unlink operations. As a result, a user process may read corrupted or incomplete file metadata, causing data integrity problems or application crashes. The vulnerability does not provide a direct execution vector, but it can lead to denial of service or brief corruption of NTFS file attributes.
Affected Systems
All Linux kernel versions that include the ntfs module are affected. Any system that mounts an NTFS filesystem—and thereby exposes the ntfs module to userspace—is potentially impacted. The flaw originates within the kernel driver and is independent of distribution or specific kernel release numbers.
Risk and Exploitability
The EPSS score is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of mass exploitation. The CVSS score of 7.1 indicates moderate severity in the Common Vulnerability Scoring System. Based on the description, it is inferred that an attacker requires local privileges to simultaneously perform a read (via mmap or file access) and a link or unlink operation on a resident NTFS file. Triggering the race could lead to temporary data corruption or denial of service, but the flaw does not appear to allow arbitrary code execution or remote compromise.
OpenCVE Enrichment