๐Ÿ” CVE Alert

CVE-2026-89616

HIGH 7.5

fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() ni_read_frame() decompresses an LZNT $DATA frame into the vmapped target pages and then trusts decompress_lznt()'s return value: unc_size = decompress_lznt(frame_ondisk, ondisk_size, frame_mem, frame_size); if ((ssize_t)unc_size < 0) err = unc_size; else if (!unc_size || unc_size > frame_size) err = -EINVAL; decompress_lznt() stops as soon as the compressed stream is exhausted (e.g. a zero chunk header) and returns the number of bytes it actually wrote, which may be far less than frame_size. The bytes between unc_size and frame_size are never written. The only memset() that follows zeroes the region beyond i_valid; when the frame lies entirely within the file's valid size that memset() does not run, so the gap retains whatever was in the just-vmapped pages. All pages are then marked uptodate and returned to userspace, disclosing uninitialized (recently-freed) kernel page memory. A crafted compressed file whose stream decompresses to only a few bytes leaks the remainder of every frame on a plain read(2), which is enough to recover kernel pointers and defeat KASLR. Zero the [unc_size, frame_size) tail immediately after a successful LZNT decompress so the remainder reads back as zero.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
4342306f0f0d5ff4315a204d315c1b51b914fca5 < 7d60a4c49af4d5cb88aa7cbf998d0408bd415055 4342306f0f0d5ff4315a204d315c1b51b914fca5 < cd40eee4923d104ebec9ac7513b971bc441e431d 4342306f0f0d5ff4315a204d315c1b51b914fca5 < 77d8efd04745cda23858546afdbd9d07b591758e 4342306f0f0d5ff4315a204d315c1b51b914fca5 < 0f699ddb290a24b37e1bc9bf1e3c9dbccf564bea 4342306f0f0d5ff4315a204d315c1b51b914fca5 < 376ee45659a4b943df672ad275c63da00655f929 4342306f0f0d5ff4315a204d315c1b51b914fca5 < 4a1b39b2e10eb8de86265e80cf2be4396bc1dce4 4342306f0f0d5ff4315a204d315c1b51b914fca5 < 35d1ea92c7d946e2ebdbe36cdb2c969c8704bebd
Linux / Linux
5.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/7d60a4c49af4d5cb88aa7cbf998d0408bd415055 git.kernel.org: https://git.kernel.org/stable/c/cd40eee4923d104ebec9ac7513b971bc441e431d git.kernel.org: https://git.kernel.org/stable/c/77d8efd04745cda23858546afdbd9d07b591758e git.kernel.org: https://git.kernel.org/stable/c/0f699ddb290a24b37e1bc9bf1e3c9dbccf564bea git.kernel.org: https://git.kernel.org/stable/c/376ee45659a4b943df672ad275c63da00655f929 git.kernel.org: https://git.kernel.org/stable/c/4a1b39b2e10eb8de86265e80cf2be4396bc1dce4 git.kernel.org: https://git.kernel.org/stable/c/35d1ea92c7d946e2ebdbe36cdb2c969c8704bebd