Executive brief
The Linux kernel's NTFS3 filesystem driver contains a buffer overflow vulnerability in its index insertion logic. When processing a crafted NTFS image with inconsistent size metadata, the driver copies more data than the destination buffer can hold, leading to heap memory corruption. An unprivileged user can trigger this vulnerability by creating files on a mounted malicious NTFS image, potentially enabling privilege escalation or system compromise.
Technical details
The vulnerability exists in the ntfs3 driver's indx_insert_into_root() function, which promotes a full resident $INDEX_ROOT to $INDEX_ALLOCATION. The function calculates a byte count ('to_move') based on on-disk resident entry sizes without validating it against the destination buffer size (determined by root->index_block_size). A crafted NTFS image with a valid, full resident root whose index_block_size is shrunk to 512 bytes after population causes hdr_insert_head() to perform a memcpy that overruns the destination by 120-136 bytes with attacker-controlled data from the on-disk entries. The write is reachable via unprivileged open(O_CREAT) on a mounted filesystem. The fix validates that 'to_move' fits within the remaining payload capacity before calling hdr_insert_head(), and returns -EINVAL on mismatch.
Affected products
- Linux Linux kernel Affected versions prior to the fix
Timeline
- 2026-08-15: disclosed
- 2026-08-15: advisory: CVE-2026-72192 assigned