Impact
The Linux kernel’s ntfs3 module contains a logic flaw in its attribute enumeration routine that validates non‑resident attributes. The check comparing the starting virtual cluster number to the ending cluster number uses an unsigned 64‑bit addition that wraps when the ending value is U64_MAX. This wrap makes the comparison succeed for a malformed on‑disk attribute that should be rejected, allowing the kernel to treat an attacker‑crafted attribute as valid and potentially read or write outside the intended bounds.
Affected Systems
Every Linux distribution shipping a kernel that has not incorporated the upstream patch is affected. The vulnerability is tied to the ntfs3 component, and no version range is provided in the advisory – the fix is referenced in upstream commit history. Any system that mounts or scans NTFS volumes using the vulnerable kernel code is exposed.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity, while the EPSS score of <1% indicates that exploitation attempts are currently uncommon. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, inferred from the need for a crafted NTFS volume or malicious file system image to trigger the kernel logic. No remote exploitation path is described in the provided data.
OpenCVE Enrichment
Debian DLA
Debian DSA