PT-2026-93391 · Linux · Linux Kernel

CVE-2026-89785

·

Published

2026-09-16

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds read exists in the NTFS3 file system. The functions ntfs reparse init() and ntfs objid init() parse the index root of the $Extend/$Reparse and $Extend/$ObjId metafiles. These functions use resident data() to read the type and rule fields of the INDEX ROOT attributes, but resident data() fails to verify if the resident attribute is large enough to contain them. When mi enum attr() accepts a resident attribute where data off equals asize and data size is 0, and this attribute is positioned last in its MFT record, resident data() returns a pointer to the end of the record size buffer. Consequently, reading root->type or root->rule results in reading past the allocated memory. This issue can be triggered when mounting a specially crafted image and requires CAP SYS ADMIN privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101345
CVE-2026-89785
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel