PT-2026-90331 · Linux · Linux

CVE-2026-89615

·

Published

2026-09-11

·

Updated

2026-09-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: bound page lcns[] index by the log record
The copy lcns loop and the redo shorten loop index page lcns[] at j + i, where i runs up to the log record's lcns follow. That count is checked only against the record's own length, not the target entry, so check dp table() (which validates the entry's lcns follow) does not cover it: the copy lcns entry may even be freshly allocated after that check, and find dp() bounds j but not i. A crafted record thus overflows page lcns[] of an otherwise valid entry.
Add dp range ok() and reject, before each loop, any record whose run does not fit the entry. These are the only two page lcns[] accesses indexed by the record rather than the entry, so together with the entry validation every access is now bounded.
[almaz.alexandrovich@paragon-software.com: original patch contained changes to the problem already handled, applied partly]
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-89615

Affected Products

Linux