Impact
In the Linux kernel’s NTFS3 driver, an integer overflow occurs while validating the Master File Table (MFT) cluster numbers read from a malformed boot sector. Bounds checks that compare the product of the cluster number and sectors per cluster against the total volume size fail to detect overflow, allowing very large values to be accepted. These values are then used to compute logical block addresses during mounting, which in turn cause low‑level block layer failures and result in mount failures. The flaw does not provide remote code execution or privilege escalation; it primarily disrupts normal operation of filesystems that rely on NTFS3.
Affected Systems
All Linux systems shipped with a kernel version that contains the legacy ntfs3 implementation before this patch are affected. The vendor products are generic Linux kernels; any distribution using a kernel that has not been updated to include the fix is impacted. The CPE for the affected platform is cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*.*
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a deliberately malformed NTFS volume with MFT cluster numbers that trigger the overflow, which is typically a local or privileged scenario. Even though the attack vector would likely be limited to environments that mount such volumes, the impact of a successful exploit is a denial of service through mount failure or system instability. Given the low exploitation probability but potential for disruption, the risk should be considered medium for systems that regularly mount NTFS partitions.
OpenCVE Enrichment
Debian DLA
Debian DSA