Executive brief
A vulnerability in the Linux kernel's NTFS file system driver could allow a system crash or memory corruption when processing a specially crafted NTFS disk image. This occurs when the system attempts to write data to a corrupted or malicious drive, potentially leading to a denial of service. Users are primarily at risk if they mount untrusted storage devices or disk images.
Technical details
An out-of-bounds (OOB) memory access vulnerability exists in the Linux kernel NTFS driver due to improper error handling in ntfs_icx_ib_sync_write(). The function calls post_write_mst_fixup() even when a preceding validation check in ntfs_ib_write() fails. Because post_write_mst_fixup() lacks its own boundary checks and assumes valid index_block contents, it can be induced to perform OOB reads or writes via a crafted NTFS image with malicious usa_ofs or usa_count values. This can lead to integer underflow or memory corruption as reported by KASAN. The fix involves moving the fixup call to ntfs_ib_write() so it only executes if initial validation succeeds.
Affected products
- Linux Linux Kernel 0a8ac0c1fa0b99a5b29002bc7f232ed7eafddef0 to e2018628301a6d9f54e34b0cb417f1688c66df1d
Timeline
- 2026-07-04: other: Patch authored
- 2026-07-25: disclosed: CVE published