{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98315","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.339Z","datePublished":"2026-10-06T08:46:10.751Z","dateUpdated":"2026-10-07T06:49:59.515Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:59.515Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: protect runlist updates with the runlist lock\n\nntfs_non_resident_attr_shrink() calls runlist helpers that require the\nrunlist write lock, but did not hold it while freeing clusters and\ntruncating the runlist. Serialize those operations and the resident\nconversion with the runlist lock.\n\nntfs_attr_map_cluster() can merge a newly allocated run before updating\nmapping pairs. If the update fails, free the clusters and restore both\nthe in-memory runlist and on-disk mapping pairs from a saved runlist.\nMark the volume in error if either rollback step fails."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The trigger is a local ftruncate() on a file in a mounted NTFS volume, via ntfs_setattr_size()->ntfs_truncate_vfs()->__ntfs_attr_truncate_vfs()->ntfs_non_resident_attr_shrink(). That path frees clusters and calls ntfs_rl_truncate_nolock() without ni->runlist.lock. No remote protocol supplies the input; it is a locking defect on a well-formed volume.\nAC:L - The attacker runs both sides of the race: one thread dirties and fsync()s the file, driving ntfs_writeback_range()->__ntfs_write_iomap_begin(), which walks and merges ni->runlist.rl under runlist.lock. Another thread repeatedly ftruncate()s the same file, reallocating or kvfree()ing rl without that lock. It can be retried at will.\nPR:L - The attacker only needs an ordinary local account with write permission on a file in an already-mounted NTFS volume, as needed for setattr ATTR_SIZE and writeback. No capability is checked on this path.\nUI:N - No crafted image or victim mount is needed. The race works against any legitimately mounted NTFS volume, using only the attacker's own truncate and write/fsync calls on a file the attacker can already write.\nS:U - The memory corruption stays within the kernel's own security authority. No guest/host, IOMMU or sandbox boundary is crossed.\nC:H - ntfs_rl_truncate_nolock() reallocates or frees the kvmalloc'd runlist array while writeback still holds a pointer into it, so the freed slab can be reclaimed and its contents read back as cluster mappings (LCNs). That can direct I/O at arbitrary disk clusters, and is a use-after-free read of kernel memory.\nI:H - The writeback path merges new runs into the freed or reallocated runlist array (heap use-after-free write). Concurrently, ntfs_cluster_free() and the shrink update the shared runlist and on-disk mapping pairs without serialization, corrupting both kernel heap memory and filesystem metadata.\nA:H - Losing the race leads to a KASAN use-after-free or oops in the runlist walk, a double kvfree, or a corrupted runlist and mapping pairs that leave the volume inconsistent and can crash later lookups."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ntfs/attrib.c","fs/ntfs/attrib.h","fs/ntfs/attrlist.c","fs/ntfs/attrlist.h","fs/ntfs/compress.c","fs/ntfs/file.c","fs/ntfs/inode.c","fs/ntfs/mft.c"],"versions":[{"version":"495e90fa334828d4119061e2726af51d0a0fb4ed","lessThan":"742797432e8c9b0dd54ecc523c185e26b09d79a0","status":"affected","versionType":"git"},{"version":"495e90fa334828d4119061e2726af51d0a0fb4ed","lessThan":"91709ba5d6d709b2b663287b7e871e2c6b480502","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ntfs/attrib.c","fs/ntfs/attrib.h","fs/ntfs/attrlist.c","fs/ntfs/attrlist.h","fs/ntfs/compress.c","fs/ntfs/file.c","fs/ntfs/inode.c","fs/ntfs/mft.c"],"versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/742797432e8c9b0dd54ecc523c185e26b09d79a0"},{"url":"https://git.kernel.org/stable/c/91709ba5d6d709b2b663287b7e871e2c6b480502"}],"title":"ntfs: protect runlist updates with the runlist lock","x_generator":{"engine":"bippy-1.2.0"}}}}