Executive brief
The NTFS3 filesystem driver in the Linux kernel contains an integer underflow vulnerability in its journal recovery code. When processing specially crafted NTFS journal records during mount, an attacker can trigger the vulnerability to cause out-of-bounds memory reads that extend 4 GiB past the intended allocation, potentially leading to information disclosure or system crash. This affects systems mounting NTFS volumes with malicious journal data.
Technical details
The vulnerability is an integer underflow in the UpdateResidentValue case of do_action() in fs/ntfs3/fslog.c (around line 3307). When on-disk journal log record header (LRH) values attr_off and redo_len are parsed such that aoff + dlen < data_off, the calculation attr->res.data_size = cpu_to_le32(aoff + dlen - data_off) underflows to approximately 4 GiB (e.g., 0xFFFFFFF9). Subsequent code reading data_size to walk the resident attribute payload then reads up to 4 GiB past the 1024-byte MFT record allocation. The attack requires a malicious NTFS volume or journal; no authentication or network access is required. The fix validates aoff against data_off and asize before the vulnerable assignment, preventing the underflow condition and rejecting malformed journal records.
Affected products
- Linux Linux kernel 5.5 through 6.18 and stable branches (fixed upstream in 6.19+)
Timeline
- 2026-08-15: disclosed
- 2026-06-02: patched: Upstream fix committed; backports to stable branches