PT-2026-104980 · Azure Linux · Kernel

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ntfs3: fix out-of-bounds read in ntfs dir emit() and hdr find e()
The bounds check in ntfs dir emit() compares fname->name len (a character count) against e->size (a byte count) without accounting for the 2-byte-per-character UTF-16LE encoding or the ATTR FILE NAME header size:
if (fname->name len + sizeof(struct NTFS DE) > le16 to cpu(e->size))
This computes: name len + 16 > e size
The correct check must account for the ATTR FILE NAME header (66 bytes before the name) and the UTF-16LE character size (2 bytes each):
sizeof(NTFS DE) + offsetof(ATTR FILE NAME, name) + name len * sizeof(short) > e size
Which computes: 16 + 66 + name len * 2 > e size
The correct calculation already exists as fname full size() in ntfs.h and is used in cmp fnames(), namei.c, and fslog.c, but was not used in the readdir path.
A crafted NTFS image with an index entry containing a small e->size but large fname->name len bypasses the current check, causing ntfs utf16 to nls() to read past the entry boundary.
Additionally, add a key size validation in hdr find e() to ensure the declared key size does not exceed the available entry data, preventing comparison functions from reading past entry boundaries on the lookup path.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103955

Affected Products

Kernel