PT-2026-104849 · Azure Linux · Kernel
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: validate index entry key bounds
[BUG]
A malformed NTFS directory index entry can advertise a key size larger
than the bytes actually present in its NTFS DE payload. Directory lookup
then passes that malformed key to cmp fnames(), which can read past the
end of the kmalloc'ed index buffer.
BUG: KASAN: slab-out-of-bounds in fname full size fs/ntfs3/ntfs.h:590 [inline]
BUG: KASAN: slab-out-of-bounds in cmp fnames+0x1ea/0x230 fs/ntfs3/index.c:46
Read of size 1 at addr ffff88801c313018 by task syz.6.3365/9279
Call Trace:
dump stack lib/dump stack.c:94 [inline]
dump stack lvl+0xbe/0x130 lib/dump stack.c:120
print address description mm/kasan/report.c:378 [inline]
print report+0xd1/0x650 mm/kasan/report.c:482
kasan report+0xfb/0x140 mm/kasan/report.c:595
asan report load1 noabort+0x14/0x30 mm/kasan/report generic.c:378
fname full size fs/ntfs3/ntfs.h:590 [inline]
cmp fnames+0x1ea/0x230 fs/ntfs3/index.c:46
hdr find e.isra.0+0x3ed/0x670 fs/ntfs3/index.c:762
indx find+0x4b5/0x900 fs/ntfs3/index.c:1186
dir search u+0x2c0/0x460 fs/ntfs3/dir.c:254
ntfs lookup+0x1cc/0x2a0 fs/ntfs3/namei.c:85
lookup slow+0x241/0x450 fs/namei.c:1816
lookup slow fs/namei.c:1833 [inline]
walk component+0x31c/0x570 fs/namei.c:2151
link path walk+0x592/0xd60 fs/namei.c:2519
path lookupat+0x138/0x660 fs/namei.c:2675
filename lookup+0x1f3/0x560 fs/namei.c:2705
filename setxattr+0xad/0x1c0 fs/xattr.c:660
path setxattrat+0x1d8/0x280 fs/xattr.c:713
do sys lsetxattr fs/xattr.c:754 [inline]
se sys lsetxattr fs/xattr.c:750 [inline]
x64 sys lsetxattr+0xd0/0x150 fs/xattr.c:750
...
Allocated by task 9279:
kasan save stack+0x39/0x70 mm/kasan/common.c:56
kasan save track+0x14/0x40 mm/kasan/common.c:77
kasan save alloc info+0x37/0x60 mm/kasan/generic.c:573
poison kmalloc redzone mm/kasan/common.c:400 [inline]
kasan kmalloc+0xc3/0xd0 mm/kasan/common.c:417
kasan kmalloc include/linux/kasan.h:262 [inline]
do kmalloc node mm/slub.c:5650 [inline]
kmalloc noprof+0x2bd/0x900 mm/slub.c:5662
kmalloc noprof include/linux/slab.h:961 [inline]
indx read+0x41d/0xad0 fs/ntfs3/index.c:1059
indx find+0x447/0x900 fs/ntfs3/index.c:1179
dir search u+0x2c0/0x460 fs/ntfs3/dir.c:254
ntfs lookup+0x1cc/0x2a0 fs/ntfs3/namei.c:85
lookup slow+0x241/0x450 fs/namei.c:1816
lookup slow fs/namei.c:1833 [inline]
walk component+0x31c/0x570 fs/namei.c:2151
link path walk+0x592/0xd60 fs/namei.c:2519
path lookupat+0x138/0x660 fs/namei.c:2675
filename lookup+0x1f3/0x560 fs/namei.c:2705
filename setxattr+0xad/0x1c0 fs/xattr.c:660
path setxattrat+0x1d8/0x280 fs/xattr.c:713
do sys lsetxattr fs/xattr.c:754 [inline]
se sys lsetxattr fs/xattr.c:750 [inline]
x64 sys lsetxattr+0xd0/0x150 fs/xattr.c:750
...
[CAUSE]
The index-header validators only validated INDEX HDR-level geometry.
They did not walk each NTFS DE to verify entry alignment, subnode
layout, or that key size fit inside the entry payload. They also
allowed a last sentinel entry to carry a non-zero key size.
[FIX]
Walk every NTFS DE in ntfs3's index-header validators and reject
entries with invalid layout, mismatched subnode state, oversized
key size, or non-zero sentinel keys before lookup or log replay can
consume them.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel