PT-2026-90333 · Linux · Linux
CVE-2026-89617
·
Publicado
2026-09-11
·
Atualizado
2026-09-11
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: validate dirty page table on log replay
Each DIR PAGE ENTRY ends in a page lcns[] array whose length is the on-disk
lcns follow field. check rstbl() validates the table bookkeeping but never
checks that this array fits in the entry, so a crafted lcns follow lets the
v0->v1 conversion memmove and later replay passes run off the entry.
Add check dp table() to reject, right after check rstbl(), any entry larger
than its size claims via struct size() (the same expression used to allocate
these entries, so the check is overflow-safe by construction). All consumers
can then trust lcns follow as the real capacity. This covers every
page lcns[] access whose index is bounded by the entry itself (the
conversion memmove, the HotFix store via find dp(), and the self-bounded
scan loops). Accesses whose index comes from the log record need a separate
bound and are handled in a follow-up patch.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux