Description
In the Linux kernel, the following vulnerability has been resolved:

ntfs: fix kmap_local_page() usage in compress

Several compressed I/O paths discard the address returned by
kmap_local_page() and later access or unmap the page using page_address().
This is invalid for highmem pages, and local mappings must also be unmapped
using the address returned by kmap_local_page().

Map each destination page in ntfs_decompress() only while producing the
current sub-block. Use memcpy_from_page(), memcpy_to_page(), and
memzero_page() for the other page accesses. Remove unnecessary local
mappings from ntfs_write_cb(), where pages are accessed through the vmap()
mapping.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Memory Corruption
Action: Apply Patch
AI Analysis

Impact

The Linux kernel contains an issue in the NTFS driver where the function kmap_local_page() is used incorrectly during compressed I/O paths. When a high‑memory page is mapped, the driver discards the address returned by kmap_local_page() and later accesses or unmapped the page using page_address(), which is invalid for high‑memory pages. This misuse can lead to kernel memory corruption, crashes, or other unintended behaviors. The patch replaces the unsafe local mapping usage with safer helper functions such as memcpy_from_page(), memcpy_to_page(), and memzero_page(), preventing the potential for corrupted memory states.

Affected Systems

The vulnerability affects the Linux operating system, specifically the Linux kernel. No specific kernel versions are listed in the data, so any kernel revision prior to the applied fix that contains the unpatched NTFS driver code could be impacted.

Risk and Exploitability

The EPSS score is reported as less than 1% and the vulnerability is not listed in CISA KEV, indicating a very low known exploitation probability. Although no CVSS score is provided, the nature of the flaw suggests a local kernel exploitation path, potentially resulting in local privilege escalation or denial‑of‑service if an attacker can write or manipulate NTFS filesystem data. Exploitation would require local access or a scenario where an attacker can trigger the affected compressed I/O path. The likely attack vector is a local kernel exploitation scenario involving NTFS operations.

Generated by OpenCVE AI on September 18, 2026 at 23:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest kernel release that includes the NTFS kmap_local_page() patch and reboot the system.
  • If NTFS support is not required, unload the ntfs kernel module or use an alternative filesystem.
  • Monitor system logs for kernel panics or crashes related to NTFS operations to validate stability after the update.

Generated by OpenCVE AI on September 18, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ntfs: fix kmap_local_page() usage in compress Several compressed I/O paths discard the address returned by kmap_local_page() and later access or unmap the page using page_address(). This is invalid for highmem pages, and local mappings must also be unmapped using the address returned by kmap_local_page(). Map each destination page in ntfs_decompress() only while producing the current sub-block. Use memcpy_from_page(), memcpy_to_page(), and memzero_page() for the other page accesses. Remove unnecessary local mappings from ntfs_write_cb(), where pages are accessed through the vmap() mapping.
Title ntfs: fix kmap_local_page() usage in compress
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:33.888Z

Reserved: 2026-09-11T19:38:34.788Z

Link: CVE-2026-90134

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:05.950

Modified: 2026-09-17T17:17:05.950

Link: CVE-2026-90134

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:00:12Z

Weaknesses