PT-2026-104980 · Azure Linux · Kernel
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ntfs3: fix out-of-bounds read in ntfs dir emit() and hdr find e()
The bounds check in ntfs dir emit() compares fname->name len (a
character count) against e->size (a byte count) without accounting
for the 2-byte-per-character UTF-16LE encoding or the ATTR FILE NAME
header size:
if (fname->name len + sizeof(struct NTFS DE) > le16 to cpu(e->size))
This computes: name len + 16 > e size
The correct check must account for the ATTR FILE NAME header (66 bytes
before the name) and the UTF-16LE character size (2 bytes each):
sizeof(NTFS DE) + offsetof(ATTR FILE NAME, name) +
name len * sizeof(short) > e size
Which computes: 16 + 66 + name len * 2 > e size
The correct calculation already exists as fname full size() in ntfs.h
and is used in cmp fnames(), namei.c, and fslog.c, but was not used
in the readdir path.
A crafted NTFS image with an index entry containing a small e->size
but large fname->name len bypasses the current check, causing
ntfs utf16 to nls() to read past the entry boundary.
Additionally, add a key size validation in hdr find e() to ensure the
declared key size does not exceed the available entry data, preventing
comparison functions from reading past entry boundaries on the lookup
path.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel