Junglewise Threat Intelligence

CVE-2026-89616: Linux kernel ntfs3 info-leak in LZNT decompress

CVE-2026-89616 · Severity: high · CVSS 7.5 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NTFS3 filesystem driver improperly handles decompression of compressed file data, potentially leaking uninitialized kernel memory to unprivileged users. An attacker with a crafted NTFS file could read sensitive data such as kernel pointers from memory, undermining kernel address space layout randomization (KASLR) protections and potentially enabling further attacks.

Technical details

The vulnerability is an information disclosure (CWE-200) in the ni_read_frame() function of fs/ntfs3/frecord.c. When decompressing LZNT-compressed NTFS file data, decompress_lznt() may return fewer decompressed bytes than the target frame size if the compressed stream is exhausted early. The remaining uninitialized buffer region—vmapped kernel pages that may contain recently-freed sensitive data—is never zeroed and is returned to userspace as valid file data. An unprivileged local user or remote attacker with access to a crafted NTFS filesystem can trigger this by reading a compressed file, allowing recovery of kernel pointers and defeating KASLR. The fix adds a memset() call to zero the [unc_size, frame_size) tail immediately after successful decompression, ensuring uninitialized memory is not disclosed.

Affected products

  • Linux Linux kernel 4.15 and later (ntfs3 driver introduced in 5.15, vulnerability present since initial merge)

Timeline

  • 2026-09-11: disclosed: Published as CVE-2026-89616
  • 2026-06-23: patched: Fix authored by Samuel Page
  • 2026-09-07: other: Fix merged into Linux stable tree

References

Related threats