Executive brief
The Linux kernel's NTFS3 filesystem driver contains a memory leak in its initialization routine. When the filesystem fails to mount, allocated mount option data is not properly freed, causing memory to accumulate and eventually exhaust system resources. This can be triggered by an unprivileged user attempting to mount a malformed NTFS volume, potentially leading to denial of service through memory exhaustion.
Technical details
This is a resource leak vulnerability in the ntfs3 filesystem driver's ntfs_fill_super() function. The vulnerability occurs when filesystem initialization fails; mount options allocated via ntfs_init_fs_context() are not freed on the error path, allowing memory to leak. An attacker can trigger this by repeatedly attempting to mount malformed NTFS volumes via the mount syscall, which requires no special privileges. While the leak is only 32 bytes per failed attempt, repeated exploitation can exhaust available kernel memory and cause denial of service. The fix is a one-line addition calling put_mount_options() on the error path before releasing other resources.
Affected products
- Linux Linux kernel Linux 5.x, 6.x and potentially earlier versions with ntfs3 driver
Timeline
- 2025-10-01: disclosed
- 2023-01-04: patched: Patch committed to stable kernel trees