Executive brief
The Linux kernel's NTFS filesystem driver has a memory leak during failed mount operations. When an NTFS volume fails to mount, several internal data structures are not properly freed, causing memory to accumulate with each failed mount attempt. This can degrade system performance and availability over time if an attacker or misconfiguration repeatedly triggers mount failures.
Technical details
The vulnerability is a resource leak in ntfs_fill_super()'s error handling path. When volume initialization fails, the cleanup code only calls kfree(vol) but does not properly release three resources: vol->nls_map (a language/character set mapping loaded via load_nls_default()), vol->volume_label (allocated during system file parsing), and vol->lcn_empty_bits_per_page (previously kvfree()'d but pointer not cleared). The error path bypasses ntfs_volume_free() and the d_make_root() inline cleanup block, so these allocations persist in kernel memory. An attacker or administrator could repeatedly trigger mount failures via malformed NTFS images or parameters, accumulating memory leaks. The fix consolidates cleanup code to ensure all resources are unconditionally freed via kvfree()/kfree()/unload_nls() at the common error exit point.
Affected products
- Linux kernel 5.0 through 6.x (NTFS driver)
Timeline
- 2026-08-15: disclosed