Junglewise Threat Intelligence

CVE-2026-53029: Linux Kernel uninitialized memory use in ntfs3 ntfs_iomap_begin

CVE-2026-53029 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's NTFS3 file system driver that could lead to system instability. The issue occurs when the system attempts to process certain file operations with zero length, potentially causing the system to use uninitialized memory. This could result in unpredictable system behavior or crashes when interacting with specifically formatted NTFS storage.

Technical details

An uninitialized value vulnerability exists in the Linux kernel's fs/ntfs3/inode.c within the ntfs_iomap_begin function. The root cause is a logic error where run_lookup_entry() can return false and set the length to zero, causing attr_data_get_block_locked() to bypass initialization of the Logical Cluster Number (LCN) variable. An attacker with local access could potentially trigger this condition to cause a kernel oops or other undefined behavior. The fix involves moving the zero-length check (clen) forward in ntfs_iomap_begin to ensure the function returns an error before the uninitialized LCN is accessed. Patches have been released for the 7.0.x stable branch and the main kernel tree.

Affected products

  • Linux Linux Kernel 7.0 to 7.0.10

Timeline

  • 2026-02-23: other: Patch authored
  • 2026-06-24: advisory: CVE published

References

Related threats