{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89611","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.734Z","datePublished":"2026-09-11T19:45:12.646Z","dateUpdated":"2026-09-13T06:31:48.805Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:31:48.805Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: validate non-resident attribute offsets\n\nntfs_attr_update_meta() shifts the attribute name when converting between\nnon-sparse and sparse attributes. Converting to sparse also adds the\ncompressed_size field before the name and mapping pairs, requiring eight\nadditional bytes in the attribute record.\n\nHowever, the validator does not check that name_offset is within safe\nboundaries for these operations or that the additional space is available.\nA malicious MFT record could set name_offset such that:\n\n1. The name is positioned at the very end of a non-sparse attribute.\n   Converting to sparse would shift the name forward by 8 bytes,\n   writing beyond the attribute boundary.\n\n2. The name overlaps with the mapping pairs, causing corruption during\n   conversion.\n\nAdd validation to ensure:\n- For named attributes, name_offset is within valid bounds\n- Name does not extend beyond the attribute or overlap with mapping pairs\n- For non-sparse, non-compressed attributes, eight bytes are available\n  after mapping_pairs_offset for the compressed_size field\n\nThe space check also covers unnamed attributes, for which name_offset = 0\nis valid and no name range needs to be checked."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - fs/ntfs registers ntfs_export_ops, so ksmbd/nfsd VFS write, truncate, create, and ksmbd vfs_fallocate(FALLOC_FL_PUNCH_HOLE) on an exported NTFS volume reach ntfs_attr_update_mapping_pairs() → ntfs_attr_update_meta() without local shell access.\nAC:L - A crafted MFT record with a malicious name_offset or too little mapping-pairs slack makes ntfs_attr_update_meta() memmove the name or add compressed_size on every attacker-driven punch-hole, sparse extend, or directory update; no race or uninfluenced layout is required.\nPR:N - Exploitation needs only write or create access on the mounted NTFS volume, including guest/anonymous SMB or world-writable NFS on a misconfigured export and automounted removable media; no init-namespace root or CAP_SYS_ADMIN is required.\nUI:N - Once the NTFS volume is rw-mounted and optionally exported (or automounted from shared/removable storage), the attacker triggers sparsity conversion via fallocate, truncate, write, or create; no further victim clicks or cooperative opens are needed.\nS:U - The overflow corrupts the kmalloc MFT-record buffer and adjacent host-kernel heap during filesystem metadata updates; this is standard kernel privilege impact, not a VM escape, IOMMU bypass, or sandbox scope change.\nC:H - memmove of the attacker-controlled attribute name and later mapping-pairs builds write past the kmalloc(mft_record_size) slab into neighboring objects, which per kernel CNA guidance yields an information-disclosure primitive from corrupted adjacent heap contents.\nI:H - Converting to or from sparse performs an out-of-bounds heap write of attacker-chosen name bytes and can shift mapping_pairs_offset so ntfs_mapping_pairs_build() stores runs past the record, enabling slab corruption and control-flow hijack.\nA:H - Overflowing the kmalloc MFT-record slab into adjacent memory can oops or panic the kernel, and even failed exploitation leaves inconsistent MFT metadata that crashes later lookups or writeback."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ntfs/attrib.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cd7b3dc7557faadeea626034e3bac68a449851ef","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a83e82b0ec3ae523028e24813f23f18b43e8fc1c","status":"affected","versionType":"git"},{"version":"0","lessThan":"7.2.4","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ntfs/attrib.c"],"versions":[{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/cd7b3dc7557faadeea626034e3bac68a449851ef"},{"url":"https://git.kernel.org/stable/c/a83e82b0ec3ae523028e24813f23f18b43e8fc1c"}],"title":"ntfs: validate non-resident attribute offsets","x_generator":{"engine":"bippy-1.2.0"}}}}