Junglewise Threat Intelligence

CVE-2026-89614: Linux kernel NTFS out-of-bounds read in cluster allocation

CVE-2026-89614 · Severity: critical · CVSS 9.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NTFS filesystem driver contains a bug in its cluster allocation logic that allows an attacker to read memory beyond the allocated bitmap array. By mounting a specially crafted NTFS volume with a malformed $Bitmap structure, an attacker can trigger an out-of-bounds access when a file is extended, potentially exposing sensitive kernel memory and causing a denial of service.

Technical details

The vulnerability is an out-of-bounds read (CWE-125) in the NTFS cluster allocator (fs/ntfs/lcnalloc.c). The root cause is a mismatch between two independent on-disk quantities: vol->lcn_empty_bits_per_page is sized from vol->nr_clusters at mount time, but ntfs_cluster_alloc() bounds its scan by the size of the $Bitmap metadata structure. A malicious or corrupted NTFS volume can have a $Bitmap that covers more clusters than the volume actually has, allowing the allocator to index past the lcn_empty_bits_per_page array. When a file is extended with a locality hint (previous LCN), the scan proceeds directly into the out-of-bounds memory. The fix clamps the scan to the actual array bounds and rejects decoded LCNs that exceed nr_clusters in the mapping pairs decoder. Attack requires mounting an untrusted NTFS volume; local or network-based depending on mount vector.

Affected products

  • Linux Linux Kernel 2.6.11 and later through 6.18 (NTFS driver)

Timeline

  • 2026-09-11: disclosed
  • 2026-08-19: patched: patch committed to mainline

References

Related threats