Description
In the Linux kernel, the following vulnerability has been resolved:

ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib()

ntfs_ir_to_ib copies all entries from index_root into a freshly allocated
index_block_size-byte buffer without verifying that the entries fit in the
available space. The entries in index_root may be larger than the usable
entry space in the index block.

This can cause OOB writes past the end of the allocation.

The validator ntfs_index_root_inconsistent() checks that entries are
self-consistent within the IR value, but never cross-checks them against
index_block_size. There is no bounds check in ntfs_ir_to_ib() before the
memcpy.

Fixing this at the sink in ntfs_ir_to_ib() since
ntfs_index_root_inconsistent() validates the logical consistency of
index_root as a structure and a root with large entries is a structurally
valid root. The bug is a size conflict of ntfs_ir_to_ib().
Also, the validator is called once per inode load in
ntfs_read_locked_inode() while ntfs_ir_to_ib() is only called during a
reparent, a check there adds no overhead to the common path.
Moreover, even a future call path that bypasses the validator would still
be protected.

With NULL as first parameter of ntfs_error(), the volume error flag is
never set by this call, so the device name will be absent from the error
message. In any case, that the caller, ntfs_ir_reparent(), prints an error
message that includes the device name on NULL returns.
I think this is the best solution available without adding
'struct super_block *sb' as a parameter to ntfs_ir_to_ib().

This heap out-of-bounds write is triggered by a crafted filesystem image,
which is not in the kernel threat model, anyway, fixing memory errors would
be nice to keep things secure.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Heap out‑of‑bounds write in the Linux NTFS module
Action: Apply kernel patch
AI Analysis

Impact

In the Linux kernel’s NTFS filesystem handler, the function ntfs_ir_to_ib() copies index entries into a newly allocated buffer without checking that the total size fits within the buffer. The entries in the index_root can be larger than the space available, which leads to a heap out‑of‑bounds write. This corruption writes past the end of the heap allocation and can overwrite adjacent kernel memory, potentially breaking kernel data structures. The vulnerability is triggered by a crafted NTFS filesystem image, meaning an attacker could generate a malicious volume that, when mounted, causes the overflow. While not part of the kernel’s official threat model, such a memory error can compromise kernel integrity and could serve as a foothold for privilege escalation if an attacker can control the image.

Affected Systems

This flaw affects all Linux kernel installations that include the NTFS filesystem module. No specific kernel version range is listed in the CVE data, so any kernel that contains the unpatched ntfs_ir_to_ib() code is potentially vulnerable. The issue is present in the generic Linux kernel source, so users of the standard kernel distribution may be impacted until the patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates moderate to high severity. The EPSS score is reported as less than 1%, indicating a very low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires delivery of a specially crafted NTFS image to the target system – a scenario that might arise from removable media or network shares – and the overflow writes to kernel heap memory, which could lead to arbitrary code execution if further leveraged. Given the low EPSS, the overall risk to most operations is limited, but because the vulnerability involves a heap overflow in kernel space, any successful exploit could be severe. The lack of an official workaround means the only reliable mitigation is to update the kernel to a version that contains the patch that adds bounds checking before the memcpy.

Generated by OpenCVE AI on September 20, 2026 at 02:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch commit that adds bounds checking to ntfs_ir_to_ib()
  • Reboot the system so that the new kernel image is loaded
  • If NTFS support is not required, disable the ntfs module or prevent auto‑mounting of NTFS volumes

Generated by OpenCVE AI on September 20, 2026 at 02:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib() ntfs_ir_to_ib copies all entries from index_root into a freshly allocated index_block_size-byte buffer without verifying that the entries fit in the available space. The entries in index_root may be larger than the usable entry space in the index block. This can cause OOB writes past the end of the allocation. The validator ntfs_index_root_inconsistent() checks that entries are self-consistent within the IR value, but never cross-checks them against index_block_size. There is no bounds check in ntfs_ir_to_ib() before the memcpy. Fixing this at the sink in ntfs_ir_to_ib() since ntfs_index_root_inconsistent() validates the logical consistency of index_root as a structure and a root with large entries is a structurally valid root. The bug is a size conflict of ntfs_ir_to_ib(). Also, the validator is called once per inode load in ntfs_read_locked_inode() while ntfs_ir_to_ib() is only called during a reparent, a check there adds no overhead to the common path. Moreover, even a future call path that bypasses the validator would still be protected. With NULL as first parameter of ntfs_error(), the volume error flag is never set by this call, so the device name will be absent from the error message. In any case, that the caller, ntfs_ir_reparent(), prints an error message that includes the device name on NULL returns. I think this is the best solution available without adding 'struct super_block *sb' as a parameter to ntfs_ir_to_ib(). This heap out-of-bounds write is triggered by a crafted filesystem image, which is not in the kernel threat model, anyway, fixing memory errors would be nice to keep things secure.
Title ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:15.758Z

Reserved: 2026-09-11T19:38:34.788Z

Link: CVE-2026-90133

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:05.837

Modified: 2026-09-18T18:17:43.133

Link: CVE-2026-90133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:30:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow