PT-2026-104980 · Azure Linux · Kernel
Publicado
2026-09-24
·
Atualizado
2026-09-24
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
ntfs3: fix out-of-bounds read in ntfs dir emit() and hdr find e()
The bounds check in ntfs dir emit() compares fname->name len (a
character count) against e->size (a byte count) without accounting
for the 2-byte-per-character UTF-16LE encoding or the ATTR FILE NAME
header size:
if (fname->name len + sizeof(struct NTFS DE) > le16 to cpu(e->size))
This computes: name len + 16 > e size
The correct check must account for the ATTR FILE NAME header (66 bytes
before the name) and the UTF-16LE character size (2 bytes each):
sizeof(NTFS DE) + offsetof(ATTR FILE NAME, name) +
name len * sizeof(short) > e size
Which computes: 16 + 66 + name len * 2 > e size
The correct calculation already exists as fname full size() in ntfs.h
and is used in cmp fnames(), namei.c, and fslog.c, but was not used
in the readdir path.
A crafted NTFS image with an index entry containing a small e->size
but large fname->name len bypasses the current check, causing
ntfs utf16 to nls() to read past the entry boundary.
Additionally, add a key size validation in hdr find e() to ensure the
declared key size does not exceed the available entry data, preventing
comparison functions from reading past entry boundaries on the lookup
path.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kernel