CVE-2026-89612
ntfs: reject invalid MFT LCNs from boot sector
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid MFT LCNs from boot sector The NTFS boot sector stores the MFT and MFTMirr locations as unsigned 64-bit LCNs, but parse_ntfs_boot_sector() decoded them into an s64. A crafted high-bit value could therefore become negative and pass the existing upper-bound check. The invalid value then propagated into the MFT zone allocator and could result in an out-of-bounds access to lcn_empty_bits_per_page.
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | Sep 11, 2026 |
| Last Updated | Sep 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for linux linux
Be the first to know when new critical vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Linux / Linux
11ccc9107dc460de28af90fac1f42404d9802735 < 8f8420b68a6f05ca2b03779d8208814ec539b9e5 11ccc9107dc460de28af90fac1f42404d9802735 < cc9d09fef78410bcd37ac05168cbd5f6dd75d3d2
Linux / Linux
7.1