Description
In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: fix integer overflow in MFT cluster validation

In ntfs_init_from_boot(), the boot sector's MFT cluster numbers are
validated against the volume size with:

if (mlcn * sct_per_clst >= sectors ||
mlcn2 * sct_per_clst >= sectors)
goto out;

mlcn and mlcn2 are u64 fields read directly from the boot sector.
sct_per_clst is bounded above by 4096 (true_sectors_per_clst() plus
the is_power_of_2() check below it), but the multiplication is done
in u64 and wraps when mlcn (or mlcn2) is large enough -- e.g. mlcn
near 2^62 with sct_per_clst == 4 wraps to 0, which compares below
any non-zero 'sectors', so the check is bypassed and the malformed
record is accepted.

The accepted mlcn is then used unchanged in

sbi->mft.lbo = mlcn << cluster_bits;

In practice the resulting reads fail at the block layer (sb_bread()
returns NULL via grow_buffers()'s check_mul_overflow() guard), so
today this manifests as mount failing in odd places rather than as
something more dangerous, but the validation step is still wrong
and there is no reason for callers to rely on the block layer to
catch a value that should never have been accepted in the first
place.

Use check_mul_overflow() to compute the two sector positions and
fail the mount if either multiplication wraps; this preserves the
existing semantics (mlcn * sct_per_clst >= sectors) instead of
switching to division (mlcn >= sectors / sct_per_clst), which
would tighten the check at edge cases where 'sectors' is not a
multiple of sct_per_clst. The check_*_overflow() style is the
one ntfs3 already uses for similar on-disk arithmetic in
fs/ntfs3/run.c.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via NTFS3 mount failure
Action: Apply patch
AI Analysis

Impact

In the Linux kernel’s NTFS3 driver, an integer overflow occurs while validating the Master File Table (MFT) cluster numbers read from a malformed boot sector. Bounds checks that compare the product of the cluster number and sectors per cluster against the total volume size fail to detect overflow, allowing very large values to be accepted. These values are then used to compute logical block addresses during mounting, which in turn cause low‑level block layer failures and result in mount failures. The flaw does not provide remote code execution or privilege escalation; it primarily disrupts normal operation of filesystems that rely on NTFS3.

Affected Systems

All Linux systems shipped with a kernel version that contains the legacy ntfs3 implementation before this patch are affected. The vendor products are generic Linux kernels; any distribution using a kernel that has not been updated to include the fix is impacted. The CPE for the affected platform is cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*.*

Risk and Exploitability

The EPSS score is reported as less than 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a deliberately malformed NTFS volume with MFT cluster numbers that trigger the overflow, which is typically a local or privileged scenario. Even though the attack vector would likely be limited to environments that mount such volumes, the impact of a successful exploit is a denial of service through mount failure or system instability. Given the low exploitation probability but potential for disruption, the risk should be considered medium for systems that regularly mount NTFS partitions.

Generated by OpenCVE AI on September 20, 2026 at 01:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the operating system kernel to the latest patched release that includes the ntfs3 integer overflow fix.
  • Reboot the system after applying the kernel update to ensure the new module is in use.
  • If a kernel update cannot be applied immediately, unload or remove the ntfs3 kernel module to prevent mounting of NTFS filesystems until the patch is applied.
  • Monitor log files (e.g., dmesg, syslog) for NTFS3‑related mount errors to detect any accidental use of the vulnerable driver.

Generated by OpenCVE AI on September 20, 2026 at 01:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-680

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix integer overflow in MFT cluster validation In ntfs_init_from_boot(), the boot sector's MFT cluster numbers are validated against the volume size with: if (mlcn * sct_per_clst >= sectors || mlcn2 * sct_per_clst >= sectors) goto out; mlcn and mlcn2 are u64 fields read directly from the boot sector. sct_per_clst is bounded above by 4096 (true_sectors_per_clst() plus the is_power_of_2() check below it), but the multiplication is done in u64 and wraps when mlcn (or mlcn2) is large enough -- e.g. mlcn near 2^62 with sct_per_clst == 4 wraps to 0, which compares below any non-zero 'sectors', so the check is bypassed and the malformed record is accepted. The accepted mlcn is then used unchanged in sbi->mft.lbo = mlcn << cluster_bits; In practice the resulting reads fail at the block layer (sb_bread() returns NULL via grow_buffers()'s check_mul_overflow() guard), so today this manifests as mount failing in odd places rather than as something more dangerous, but the validation step is still wrong and there is no reason for callers to rely on the block layer to catch a value that should never have been accepted in the first place. Use check_mul_overflow() to compute the two sector positions and fail the mount if either multiplication wraps; this preserves the existing semantics (mlcn * sct_per_clst >= sectors) instead of switching to division (mlcn >= sectors / sct_per_clst), which would tighten the check at edge cases where 'sectors' is not a multiple of sct_per_clst. The check_*_overflow() style is the one ntfs3 already uses for similar on-disk arithmetic in fs/ntfs3/run.c.
Title fs/ntfs3: fix integer overflow in MFT cluster validation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:18.182Z

Reserved: 2026-09-11T19:38:34.792Z

Link: CVE-2026-90200

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:14.930

Modified: 2026-09-17T17:17:14.930

Link: CVE-2026-90200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:45:17Z

Weaknesses
  • CWE-680

    Integer Overflow to Buffer Overflow