PT-2026-98073 · Linux · Linux

CVE-2026-97439

·

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: preserve non-DOS attribute bits in system.dos attrib
[BUG] A corrupted ntfs3 image can hit a NULL function pointer call in generic perform write() after toggling system.ntfs attrib and then overwriting system.dos attrib on the same file.
BUG: kernel NULL pointer dereference, address: 0000000000000000 #PF: supervisor instruction fetch in kernel mode #PF: error code(0x0010) - not-present page PGD bed5067 P4D bed5067 PUD 0 Oops: Oops: 0010 [#1] SMP KASAN NOPTI RIP: 0010:0x0 Code: Unable to access opcode bytes at 0xffffffffffffffd6. RSP: 0018:ffff88801025f988 EFLAGS: 00010246 Call Trace: generic perform write+0x409/0x8c0 mm/filemap.c:4255 generic file write iter+0x1bb/0x200 mm/filemap.c:4372 ntfs file write iter+0xcd9/0x1c20 fs/ntfs3/file.c:1253 new sync write fs/read write.c:593 [inline] vfs write+0x63b/0xf70 fs/read write.c:686 ksys write+0x133/0x250 fs/read write.c:738 do sys write fs/read write.c:749 [inline] se sys write fs/read write.c:746 [inline] x64 sys write+0x77/0xc0 fs/read write.c:746 ...
[CAUSE] system.ntfs attrib updates ATTR DATA flags via ni new attr flags() and switches i mapping->a ops to ntfs aops cmpr when FILE ATTRIBUTE COMPRESSED is set. system.dos attrib then overwrites ni->std fa from a one-byte DOS attribute value, clearing the compression bit without updating ATTR DATA or the mapping operations.
Old buffered writes use is compressed(ni) to choose generic file write iter(). That leaves generic perform write() calling a NULL write begin callback from ntfs aops cmpr.
[FIX] Treat system.dos attrib as a low-byte DOS attribute update and preserve the existing non-DOS attribute bits in ni->std fa. This keeps compressed and sparse state consistent with ATTR DATA and the mapping operations while keeping the existing DOS attribute semantics intact.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97439

Affected Products

Linux