{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89613","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.735Z","datePublished":"2026-09-11T19:45:14.081Z","dateUpdated":"2026-09-13T06:31:51.266Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:31:51.266Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: reject invalid empty mapping pairs\n\nReject an attribute with empty mapping pairs if it has inconsistent\nhighest VCN and size."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - fs/ntfs registers ntfs_export_ops, so nfsd/ksmbd VFS reads on an exported NTFS volume reach ntfs_map_runlist()->ntfs_mapping_pairs_decompress() for crafted on-disk mapping pairs without local shell access.\nAC:L - The attacker fully controls the empty mapping-pairs terminator, lowest/highest VCN, and allocated/data/initialized sizes; decompressing that attribute and merging the resulting degenerate runlist is deterministic with no race or victim-specific layout.\nPR:N - Triggering the decoder needs only permission to cause server-side parsing of mounted NTFS metadata (guest/anonymous SMB or a permissive NFS export, or an unprivileged open/read on an already-mounted volume), not init-namespace root or CAP_SYS_ADMIN at trigger time.\nUI:N - After the crafted volume is mounted and exported, ordinary remote or local reads decompress the invalid empty mapping pairs and enter the merge path; no extra victim mount dialog, USB insertion, or confirmation is required during the attack.\nS:U - Heap corruption of the in-memory runlist and subsequent misdirected cluster I/O remain in the host kernel security domain and do not cross a VM, container, or IOMMU boundary to another authority.\nC:H - Merging the degenerate unmapped runlist computes a negative source size and indexes src+ssize-1 / dst[marker] outside the allocation, an unbounded kernel heap out-of-bounds read that can disclose adjacent objects.\nI:H - The same merge performs out-of-bounds runlist writes via marker/loc arithmetic with ssize<0 and later I/O using corrupted VCN/LCN mappings, a kernel heap write primitive sufficient for control-flow hijacking.\nA:H - WARN_ON on an entirely unmapped source runlist, heap out-of-bounds access, and corrupted runlist walks oops or panic the kernel, fully denying availability even when exploitation is not completed."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ntfs/runlist.c"],"versions":[{"version":"11ccc9107dc460de28af90fac1f42404d9802735","lessThan":"b0cc6dbc655e037251874b3e0dd1a760dcf29007","status":"affected","versionType":"git"},{"version":"11ccc9107dc460de28af90fac1f42404d9802735","lessThan":"766062a82e1ce4087c7dc077224144dfd34b3661","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ntfs/runlist.c"],"versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b0cc6dbc655e037251874b3e0dd1a760dcf29007"},{"url":"https://git.kernel.org/stable/c/766062a82e1ce4087c7dc077224144dfd34b3661"}],"title":"ntfs: reject invalid empty mapping pairs","x_generator":{"engine":"bippy-1.2.0"}}}}