PT-2026-90331 · Linux · Linux
CVE-2026-89615
·
Publicado
2026-09-11
·
Atualizado
2026-09-11
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: bound page lcns[] index by the log record
The copy lcns loop and the redo shorten loop index page lcns[] at j + i,
where i runs up to the log record's lcns follow. That count is checked only
against the record's own length, not the target entry, so check dp table()
(which validates the entry's lcns follow) does not cover it: the copy lcns
entry may even be freshly allocated after that check, and find dp() bounds j
but not i. A crafted record thus overflows page lcns[] of an otherwise valid
entry.
Add dp range ok() and reject, before each loop, any record whose run does
not fit the entry. These are the only two page lcns[] accesses indexed by
the record rather than the entry, so together with the entry validation
every access is now bounded.
[almaz.alexandrovich@paragon-software.com: original patch contained changes to the problem already handled, applied partly]
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux