PT-2026-94479 · Linux · Linux Kernel

CVE-2026-90131

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A data race exists in the NTFS driver when handling resident iomap reads. The function ntfs read iomap begin resident() traverses the Master File Table (MFT) record via ntfs attr lookup() and ntfs attr find() without acquiring the ni->mrec lock. Simultaneously, other functions such as ntfs attr record resize(), ntfs make room for attr(), and ntfs resident attr record add() may modify the same base ni->mrec buffer while holding that lock. This allows a reader to observe inconsistent or torn attribute length and offset fields during record relocation, specifically affecting the mft record.bytes in use field. This race condition was identified between the mmap read fault path and the link() and unlink() operations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90131
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel