{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90133","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.788Z","datePublished":"2026-09-17T16:06:33.234Z","dateUpdated":"2026-09-18T17:53:15.758Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:53:15.758Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: Fix index_root heap OOB write in ntfs_ir_to_ib()\n\nntfs_ir_to_ib copies all entries from index_root into a freshly allocated\nindex_block_size-byte buffer without verifying that the entries fit in the\navailable space. The entries in index_root may be larger than the usable\nentry space in the index block.\n\nThis can cause OOB writes past the end of the allocation.\n\nThe validator ntfs_index_root_inconsistent() checks that entries are\nself-consistent within the IR value, but never cross-checks them against\nindex_block_size. There is no bounds check in ntfs_ir_to_ib() before the\nmemcpy.\n\nFixing this at the sink in ntfs_ir_to_ib() since\nntfs_index_root_inconsistent() validates the logical consistency of\nindex_root as a structure and a root with large entries is a structurally\nvalid root. The bug is a size conflict of ntfs_ir_to_ib().\nAlso, the validator is called once per inode load in\nntfs_read_locked_inode() while ntfs_ir_to_ib() is only called during a\nreparent, a check there adds no overhead to the common path.\nMoreover, even a future call path that bypasses the validator would still\nbe protected.\n\nWith NULL as first parameter of ntfs_error(), the volume error flag is\nnever set by this call, so the device name will be absent from the error\nmessage. In any case, that the caller, ntfs_ir_reparent(), prints an error\nmessage that includes the device name on NULL returns.\nI think this is the best solution available without adding\n'struct super_block *sb' as a parameter to ntfs_ir_to_ib().\n\nThis heap out-of-bounds write is triggered by a crafted filesystem image,\nwhich is not in the kernel threat model, anyway, fixing memory errors would\nbe nice to keep  things secure."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The overflow source is on-disk $INDEX_ROOT (ir->index_block_size and the resident entries) that ntfs_ir_to_ib() memcpy()s; the trigger is vfs_create/mkdir/link/rename → ntfs_create/__ntfs_link → ntfs_index_add_filename → ntfs_ie_add → ntfs_ir_make_space → ntfs_ir_reparent. No protocol message carries those fields.\nAC:L - ntfs_read_locked_inode() accepts any power-of-two index_block_size in [512, PAGE_SIZE] and ntfs_index_root_inconsistent() never compares entry bytes to that size, so a 512-byte IB plus a packed resident INDEX_ROOT in a full MFT record makes ntfs_ir_truncate() return -ENOSPC and ntfs_ir_reparent() run on the next create, with no race.\nPR:N - mount_capable() needs init-namespace CAP_SYS_ADMIN because ntfs_fs_type lacks FS_USERNS_MOUNT; that mount is the victim or udisks2/vold action (UI:R), not attacker privilege. After mount, ntfs_create() is an ordinary VFS create on a directory whose mode the image controls, so the attacker needs no account.\nUI:R - ntfs_ir_to_ib() is called only from ntfs_ir_reparent(), not from ntfs_fill_super(), so attaching the volume is not enough. A victim or automounter must mount the attacker-supplied NTFS image, and then create/mkdir/link/rename must add a filename so ntfs_ie_add() takes the ENOSPC reparent path.\nS:U - The kvzalloc(index_block) overflow in ntfs_ir_to_ib() corrupts host-kernel heap in the same OS authority as fs/ntfs; it is in-kernel memory corruption, not a VM escape, IOMMU bypass, or sandbox breakout.\nC:H - memcpy() in ntfs_ir_to_ib() writes attacker-controlled INDEX_ROOT entry bytes (UTF-16 names, MFT refs) past the kvzalloc(ir->index_block_size) object into adjacent slab, a heap OOB write that can be groomed to disclose neighboring kernel objects.\nI:H - The same memcpy is an unbounded heap out-of-bounds write of attacker-chosen index-entry contents past the allocated index_block, which can corrupt adjacent slab objects and hijack kernel control flow.\nA:H - Writing past the kvzalloc index_block into unmapped or poisoned adjacent heap oopses or panics on the ntfs_ir_reparent() create/mkdir path, fully denying availability even when the overflow is not turned into a write primitive."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ntfs/index.c"],"versions":[{"version":"0a8ac0c1fa0b99a5b29002bc7f232ed7eafddef0","lessThan":"825dec5120933e90c54e30e31ccfa6c3449043a8","status":"affected","versionType":"git"},{"version":"0a8ac0c1fa0b99a5b29002bc7f232ed7eafddef0","lessThan":"dc09bf79b76f9a7157e225f449655f3f62f96c9c","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ntfs/index.c"],"versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/825dec5120933e90c54e30e31ccfa6c3449043a8"},{"url":"https://git.kernel.org/stable/c/dc09bf79b76f9a7157e225f449655f3f62f96c9c"}],"title":"ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib()","x_generator":{"engine":"bippy-1.2.0"}}}}