๐Ÿ” CVE Alert

CVE-2026-64533

UNKNOWN 0.0

fs/ntfs3: validate lcns_follow in log_replay conversion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate lcns_follow in log_replay conversion log_replay() converts DIR_PAGE_ENTRY_32 records into DIR_PAGE_ENTRY records when replaying version 0 restart tables. During this conversion, the memmove() length is derived directly from the on-disk lcns_follow field: memmove(&dp->vcn, &dp0->vcn_low, 2 * sizeof(u64) + le32_to_cpu(dp->lcns_follow) * sizeof(u64)); check_rstbl() validates restart table structure, but does not constrain per-entry lcns_follow values relative to the entry size. A malformed filesystem image can provide an oversized lcns_follow value, causing the conversion memmove() to access memory beyond the bounds of the allocated restart table buffer. The same field is later used to bound iteration over page_lcns[], so validating lcns_follow during conversion also prevents downstream out-of-bounds access from the same malformed metadata. Compute the maximum valid lcns_follow from the already-validated restart table entry size and reject entries that exceed this bound. Reuse the existing t16/t32 scratch variables already declared in log_replay() to avoid introducing new declarations. [[email protected]: fixed the conflicts]

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 27, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
b46acd6a6a627d876898e1c84d3f84902264b445 < ca343a99806b4fc8e27c48f08be3445c5fcd1445 b46acd6a6a627d876898e1c84d3f84902264b445 < ddfc8683e1a627dbf1b83bacf8961443dd654258 b46acd6a6a627d876898e1c84d3f84902264b445 < 57c071e2c4f30b9c6f5aacb6679aab1269fbae99 b46acd6a6a627d876898e1c84d3f84902264b445 < 159f694d682e4215b3822ae31ed3a4631628fe55 b46acd6a6a627d876898e1c84d3f84902264b445 < 7adb38279812c9c06b0e3fa7382f4d7887f3fa2d b46acd6a6a627d876898e1c84d3f84902264b445 < 32b9f8733feb241627fa5f564b1a99b5cae974c5 b46acd6a6a627d876898e1c84d3f84902264b445 < 6a4c53a2e26a865565bd6a460961e8d6fcb32329
Linux / Linux
5.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ca343a99806b4fc8e27c48f08be3445c5fcd1445 git.kernel.org: https://git.kernel.org/stable/c/ddfc8683e1a627dbf1b83bacf8961443dd654258 git.kernel.org: https://git.kernel.org/stable/c/57c071e2c4f30b9c6f5aacb6679aab1269fbae99 git.kernel.org: https://git.kernel.org/stable/c/159f694d682e4215b3822ae31ed3a4631628fe55 git.kernel.org: https://git.kernel.org/stable/c/7adb38279812c9c06b0e3fa7382f4d7887f3fa2d git.kernel.org: https://git.kernel.org/stable/c/32b9f8733feb241627fa5f564b1a99b5cae974c5 git.kernel.org: https://git.kernel.org/stable/c/6a4c53a2e26a865565bd6a460961e8d6fcb32329