PT-2026-104849 · Azure Linux · Kernel

Publicado

2026-09-24

·

Atualizado

2026-09-24

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: validate index entry key bounds
[BUG] A malformed NTFS directory index entry can advertise a key size larger than the bytes actually present in its NTFS DE payload. Directory lookup then passes that malformed key to cmp fnames(), which can read past the end of the kmalloc'ed index buffer.
BUG: KASAN: slab-out-of-bounds in fname full size fs/ntfs3/ntfs.h:590 [inline] BUG: KASAN: slab-out-of-bounds in cmp fnames+0x1ea/0x230 fs/ntfs3/index.c:46 Read of size 1 at addr ffff88801c313018 by task syz.6.3365/9279
Call Trace: dump stack lib/dump stack.c:94 [inline] dump stack lvl+0xbe/0x130 lib/dump stack.c:120 print address description mm/kasan/report.c:378 [inline] print report+0xd1/0x650 mm/kasan/report.c:482 kasan report+0xfb/0x140 mm/kasan/report.c:595 asan report load1 noabort+0x14/0x30 mm/kasan/report generic.c:378 fname full size fs/ntfs3/ntfs.h:590 [inline] cmp fnames+0x1ea/0x230 fs/ntfs3/index.c:46 hdr find e.isra.0+0x3ed/0x670 fs/ntfs3/index.c:762 indx find+0x4b5/0x900 fs/ntfs3/index.c:1186 dir search u+0x2c0/0x460 fs/ntfs3/dir.c:254 ntfs lookup+0x1cc/0x2a0 fs/ntfs3/namei.c:85 lookup slow+0x241/0x450 fs/namei.c:1816 lookup slow fs/namei.c:1833 [inline] walk component+0x31c/0x570 fs/namei.c:2151 link path walk+0x592/0xd60 fs/namei.c:2519 path lookupat+0x138/0x660 fs/namei.c:2675 filename lookup+0x1f3/0x560 fs/namei.c:2705 filename setxattr+0xad/0x1c0 fs/xattr.c:660 path setxattrat+0x1d8/0x280 fs/xattr.c:713 do sys lsetxattr fs/xattr.c:754 [inline] se sys lsetxattr fs/xattr.c:750 [inline] x64 sys lsetxattr+0xd0/0x150 fs/xattr.c:750 ...
Allocated by task 9279: kasan save stack+0x39/0x70 mm/kasan/common.c:56 kasan save track+0x14/0x40 mm/kasan/common.c:77 kasan save alloc info+0x37/0x60 mm/kasan/generic.c:573 poison kmalloc redzone mm/kasan/common.c:400 [inline] kasan kmalloc+0xc3/0xd0 mm/kasan/common.c:417 kasan kmalloc include/linux/kasan.h:262 [inline] do kmalloc node mm/slub.c:5650 [inline] kmalloc noprof+0x2bd/0x900 mm/slub.c:5662 kmalloc noprof include/linux/slab.h:961 [inline] indx read+0x41d/0xad0 fs/ntfs3/index.c:1059 indx find+0x447/0x900 fs/ntfs3/index.c:1179 dir search u+0x2c0/0x460 fs/ntfs3/dir.c:254 ntfs lookup+0x1cc/0x2a0 fs/ntfs3/namei.c:85 lookup slow+0x241/0x450 fs/namei.c:1816 lookup slow fs/namei.c:1833 [inline] walk component+0x31c/0x570 fs/namei.c:2151 link path walk+0x592/0xd60 fs/namei.c:2519 path lookupat+0x138/0x660 fs/namei.c:2675 filename lookup+0x1f3/0x560 fs/namei.c:2705 filename setxattr+0xad/0x1c0 fs/xattr.c:660 path setxattrat+0x1d8/0x280 fs/xattr.c:713 do sys lsetxattr fs/xattr.c:754 [inline] se sys lsetxattr fs/xattr.c:750 [inline] x64 sys lsetxattr+0xd0/0x150 fs/xattr.c:750 ...
[CAUSE] The index-header validators only validated INDEX HDR-level geometry. They did not walk each NTFS DE to verify entry alignment, subnode layout, or that key size fit inside the entry payload. They also allowed a last sentinel entry to carry a non-zero key size.
[FIX] Walk every NTFS DE in ntfs3's index-header validators and reject entries with invalid layout, mismatched subnode state, oversized key size, or non-zero sentinel keys before lookup or log replay can consume them.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

AZL-103556

Produtos afetados

Kernel