๐Ÿ” CVE Alert

CVE-2026-89779

UNKNOWN 0.0

fs/ntfs3: validate ef->size covers the record's name and value

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's name and value When an EA record has a non-zero ef->size, ntfs_read_ea() only checks that the record fits in the remaining buffer (ea_size > bytes), not that ef->size is large enough to hold the record's own name_len + 1 + elength. A crafted image can pass validation with, e.g., ef->size = 24 but elength = 0xffff. ntfs_get_ea() then trusts elength and copies it out of the undersized record, reading past the kmalloc(info->size) allocation and leaking heap memory to userspace via getxattr(): BUG: KASAN: slab-out-of-bounds in ntfs_get_ea (fs/ntfs3/xattr.c:302) Read of size 65535 at addr ffff888100794550 by task exploit __asan_memcpy (mm/kasan/shadow.c:105) ntfs_get_ea (fs/ntfs3/xattr.c:302) ntfs_getxattr (fs/ntfs3/xattr.c:848) __vfs_getxattr (fs/xattr.c:441) vfs_getxattr (fs/xattr.c:474) do_getxattr (fs/xattr.c:800) path_getxattrat (fs/xattr.c:868) do_syscall_64 (arch/x86/entry/syscall_64.c:94) The buggy address is located 80 bytes inside of allocated 84-byte region in cache kmalloc-96 Compute the size the record needs and require ef->size to cover it.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
333feb7ba84f69f9b423422417aaac54fd9e7c84 < b27e68ad818a4ca2cef8f35f97e75d756714c818 000a9a72efa4a9df289bab9c9e8ba1639c72e0d6 < 28a924c7e67e6d71abeb04860b61166fecb027fc 0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b < d585ed08308909c7e6fefb4e8a258aeb29b19ff9 0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b < 077df8464cf24f8ffc82fb6efec2ae600686e699 0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b < aab1880058ac767d3ea9388a9a7221c776c22c44 0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b < c8a109c9e23a2c7fd548473dde728b2cb8188146 0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b < c22f91d82cb9a29d22bdffdce6c803467984ad0c 5.15.121 < 5.15.221 6.1.40 < 6.1.188
Linux / Linux
6.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b27e68ad818a4ca2cef8f35f97e75d756714c818 git.kernel.org: https://git.kernel.org/stable/c/28a924c7e67e6d71abeb04860b61166fecb027fc git.kernel.org: https://git.kernel.org/stable/c/d585ed08308909c7e6fefb4e8a258aeb29b19ff9 git.kernel.org: https://git.kernel.org/stable/c/077df8464cf24f8ffc82fb6efec2ae600686e699 git.kernel.org: https://git.kernel.org/stable/c/aab1880058ac767d3ea9388a9a7221c776c22c44 git.kernel.org: https://git.kernel.org/stable/c/c8a109c9e23a2c7fd548473dde728b2cb8188146 git.kernel.org: https://git.kernel.org/stable/c/c22f91d82cb9a29d22bdffdce6c803467984ad0c