Impact
The Linux kernel’s NTFS driver permitted userspace processes that lacked CAP_SYS_ADMIN to set extended attributes with names beginning with $LX. These $LXUID, $LXGID, $LXMOD, and $LXDEV attributes govern the owner, group, mode, and device node of a file on an NTFS volume. Allowing an unprivileged process to modify them enables an attacker to alter file ownership and permissions, effectively escalating privileges or bypassing intended file access controls.
Affected Systems
All Linux kernel builds are potentially impacted until the patch that rejects unprivileged writes to $LX* xattrs is applied. The flaw is publicised for the mainline kernel, and any distributions that ship an unpatched kernel are at risk.
Risk and Exploitability
The CVSS score of 7.1 classifies this as a high‑severity vulnerability, yet the EPSS score of less than 1 % indicates a very low exploitation probability at present. The flaw is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is local, requiring a user with the ability to execute arbitrary code in the kernel context on the affected host. Successful exploitation would allow the attacker to modify file attributes and potentially gain elevated privileges via crafted ownership changes.
OpenCVE Enrichment