PT-2026-64856 · Linux · Linux Kernel

CVE-2026-64532

·

Published

2026-07-27

·

Updated

2026-08-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the NTFS3 file system where the do action() function fails to properly validate the view.data off field of an on-disk NTFS DE within an INDEX ROOT or INDEX BUFFER. Specifically, in the UpdateRecordDataRoot and UpdateRecordDataAllocation cases, the memmove() function uses a destination calculated from view.data off without verifying if view.data off plus the data length exceeds the entry size e->size. This lack of validation can lead to an out-of-bounds write, where data is written past the end of the NTFS DE.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-93971
CVE-2026-64532
OPENSUSE-SU-2026:11476-1

Affected Products

Linux Kernel