Impact
In the Linux kernel’s NTFS filesystem handler, the function ntfs_ir_to_ib() copies index entries into a newly allocated buffer without checking that the total size fits within the buffer. The entries in the index_root can be larger than the space available, which leads to a heap out‑of‑bounds write. This corruption writes past the end of the heap allocation and can overwrite adjacent kernel memory, potentially breaking kernel data structures. The vulnerability is triggered by a crafted NTFS filesystem image, meaning an attacker could generate a malicious volume that, when mounted, causes the overflow. While not part of the kernel’s official threat model, such a memory error can compromise kernel integrity and could serve as a foothold for privilege escalation if an attacker can control the image.
Affected Systems
This flaw affects all Linux kernel installations that include the NTFS filesystem module. No specific kernel version range is listed in the CVE data, so any kernel that contains the unpatched ntfs_ir_to_ib() code is potentially vulnerable. The issue is present in the generic Linux kernel source, so users of the standard kernel distribution may be impacted until the patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity. The EPSS score is reported as less than 1%, indicating a very low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires delivery of a specially crafted NTFS image to the target system – a scenario that might arise from removable media or network shares – and the overflow writes to kernel heap memory, which could lead to arbitrary code execution if further leveraged. Given the low EPSS, the overall risk to most operations is limited, but because the vulnerability involves a heap overflow in kernel space, any successful exploit could be severe. The lack of an official workaround means the only reliable mitigation is to update the kernel to a version that contains the patch that adds bounds checking before the memcpy.
OpenCVE Enrichment