๐Ÿ” CVE Alert

CVE-2026-89617

HIGH 7.8

fs/ntfs3: validate dirty page table on log replay

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate dirty page table on log replay Each DIR_PAGE_ENTRY ends in a page_lcns[] array whose length is the on-disk lcns_follow field. check_rstbl() validates the table bookkeeping but never checks that this array fits in the entry, so a crafted lcns_follow lets the v0->v1 conversion memmove and later replay passes run off the entry. Add check_dp_table() to reject, right after check_rstbl(), any entry larger than its size claims via struct_size() (the same expression used to allocate these entries, so the check is overflow-safe by construction). All consumers can then trust lcns_follow as the real capacity. This covers every page_lcns[] access whose index is bounded by the entry itself (the conversion memmove, the HotFix store via find_dp(), and the self-bounded scan loops). Accesses whose index comes from the log record need a separate bound and are handled in a follow-up patch.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
b46acd6a6a627d876898e1c84d3f84902264b445 < 0e07ea2fc45a7b4757ef7bf1f692cc0180a08323 b46acd6a6a627d876898e1c84d3f84902264b445 < 1e90b1703ee1a04cd3e9e399353fc536f5f3ba10 b46acd6a6a627d876898e1c84d3f84902264b445 < d23155634a4bc1183e761d5eb2c043b2e693cc98 b46acd6a6a627d876898e1c84d3f84902264b445 < 1200c2779c43b62656ccbb67df9468a7a9af2484 b46acd6a6a627d876898e1c84d3f84902264b445 < 2d94ffc9d7b5bb3517b129fe63b52d84bcd4ae56 b46acd6a6a627d876898e1c84d3f84902264b445 < 0908da07c23be4f94b99dfd9a94765525f0fe4bd b46acd6a6a627d876898e1c84d3f84902264b445 < 006cb7713dec10368e699abc4367e5faa334c9a5
Linux / Linux
5.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/0e07ea2fc45a7b4757ef7bf1f692cc0180a08323 git.kernel.org: https://git.kernel.org/stable/c/1e90b1703ee1a04cd3e9e399353fc536f5f3ba10 git.kernel.org: https://git.kernel.org/stable/c/d23155634a4bc1183e761d5eb2c043b2e693cc98 git.kernel.org: https://git.kernel.org/stable/c/1200c2779c43b62656ccbb67df9468a7a9af2484 git.kernel.org: https://git.kernel.org/stable/c/2d94ffc9d7b5bb3517b129fe63b52d84bcd4ae56 git.kernel.org: https://git.kernel.org/stable/c/0908da07c23be4f94b99dfd9a94765525f0fe4bd git.kernel.org: https://git.kernel.org/stable/c/006cb7713dec10368e699abc4367e5faa334c9a5