Executive brief
A vulnerability was identified in the Linux kernel's NTFS3 file system driver, which is used to read and write Windows-formatted drives. Under certain conditions when writing compressed data, the system could use uninitialized memory, potentially leading to unpredictable system behavior or the exposure of sensitive data from previous system operations. This issue has been resolved in recent kernel updates.
Technical details
An uninitialized memory usage vulnerability was discovered in the fs/ntfs3 component of the Linux kernel. The issue occurs in ntfs_get_frame_pages() when new folios are allocated without being marked as 'uptodate'. If ni_read_frame() is skipped—typically when the caller expects a frame to be completely overwritten—certain reserved folios may remain only partially filled. This leaves residual data in memory uninitialized, which is subsequently accessed by longest_match_std() during ntfs_compress_write(). An attacker with local access could potentially exploit this to read sensitive information from kernel memory. The fix involves adding the __GFP_ZERO flag to folio allocations to ensure memory is zero-initialized before use.
Affected products
- Linux Linux Kernel ntfs3 driver
Timeline
- 2025-12-19: patched: Initial patch committed to mainline kernel
- 2026-05-27: advisory: CVE published in NVD