Executive brief
The Linux kernel's NTFS3 file system driver contains a buffer overflow vulnerability in its NTFS journal processing code. A malicious or corrupted NTFS disk image can trigger an out-of-bounds memory write when the kernel attempts to delete an index entry, potentially causing a kernel crash or allowing privilege escalation. Systems that mount untrusted NTFS volumes are at risk.
Technical details
This is a heap buffer overflow in fs/ntfs3/fslog.c within the do_action() function's DeleteIndexEntryAllocation case. The vulnerability occurs when processing INDEX_BUFFER entries with crafted sizes: an attacker-controlled e->size value can cause pointer arithmetic to underflow, resulting in a negative ptrdiff_t that is silently cast to a quasi-infinite size_t. This enormous size is then passed to memmove(), which writes far past the destination buffer boundary. The fix adds three validation guards: rejecting zero-sized entries, ensuring the entry endpoint does not exceed the used buffer boundary, and checking the computed memmove length is valid. The vulnerability requires local access (mounting a crafted disk image) and is reproducible via UML+KASAN with a malformed NTFS image.
Affected products
- Linux Linux kernel all versions with NTFS3 support (Linux 5.15+)
Timeline
- 2026-08-15: disclosed
- 2026-07-24: patched: Fix committed upstream; distributed to stable branches