Executive brief
The Linux kernel's NTFS filesystem driver contains a bug in its cluster allocation logic that allows an attacker to read memory beyond the allocated bitmap array. By mounting a specially crafted NTFS volume with a malformed $Bitmap structure, an attacker can trigger an out-of-bounds access when a file is extended, potentially exposing sensitive kernel memory and causing a denial of service.
Technical details
The vulnerability is an out-of-bounds read (CWE-125) in the NTFS cluster allocator (fs/ntfs/lcnalloc.c). The root cause is a mismatch between two independent on-disk quantities: vol->lcn_empty_bits_per_page is sized from vol->nr_clusters at mount time, but ntfs_cluster_alloc() bounds its scan by the size of the $Bitmap metadata structure. A malicious or corrupted NTFS volume can have a $Bitmap that covers more clusters than the volume actually has, allowing the allocator to index past the lcn_empty_bits_per_page array. When a file is extended with a locality hint (previous LCN), the scan proceeds directly into the out-of-bounds memory. The fix clamps the scan to the actual array bounds and rejects decoded LCNs that exceed nr_clusters in the mapping pairs decoder. Attack requires mounting an untrusted NTFS volume; local or network-based depending on mount vector.
Affected products
- Linux Linux Kernel 2.6.11 and later through 6.18 (NTFS driver)
Timeline
- 2026-09-11: disclosed
- 2026-08-19: patched: patch committed to mainline