PT-2026-90331 · Linux · Linux

CVE-2026-89615

·

Publicado

2026-09-11

·

Atualizado

2026-09-11

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: bound page lcns[] index by the log record
The copy lcns loop and the redo shorten loop index page lcns[] at j + i, where i runs up to the log record's lcns follow. That count is checked only against the record's own length, not the target entry, so check dp table() (which validates the entry's lcns follow) does not cover it: the copy lcns entry may even be freshly allocated after that check, and find dp() bounds j but not i. A crafted record thus overflows page lcns[] of an otherwise valid entry.
Add dp range ok() and reject, before each loop, any record whose run does not fit the entry. These are the only two page lcns[] accesses indexed by the record rather than the entry, so together with the entry validation every access is now bounded.
[almaz.alexandrovich@paragon-software.com: original patch contained changes to the problem already handled, applied partly]
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-89615

Produtos afetados

Linux