Junglewise Threat Intelligence

CVE-2026-90118: Linux kernel NTFS off-by-one page overflow in ntfs_decompress

CVE-2026-90118 · Severity: high · CVSS 7.8 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NTFS file system driver contains an off-by-one error in the decompression routine that processes compressed NTFS file data. When reading a specially crafted compressed file with malformed attributes, the vulnerability allows memory writes to overflow past the allocated page boundary into adjacent system memory, potentially causing system instability or data corruption.

Technical details

The vulnerability is a buffer overflow in the ntfs_decompress() function in fs/ntfs/compress.c. The per-token range check uses the condition `dp_addr > dp_sb_end` instead of `dp_addr >= dp_sb_end`, allowing a single byte to be written when dp_addr equals dp_sb_end, which writes one byte past the destination page boundary. Since NTFS_SB_SIZE equals PAGE_SIZE, the destination is a single page, and the overflow byte lands in an adjacent page. This leaves the destination offset marker beyond the sub-block end, causing subsequent sub-blocks to continue writing further out-of-bounds. The attack vector requires reading a file with a corrupted compressed $DATA attribute from an NTFS volume. The fix changes the condition to `dp_addr >= dp_sb_end` to break before the overflow write. A patch is available in Linux kernel commit 98716c9fce21f6c8a9d71e08cf53e7504fa562f4.

Affected products

  • Linux Linux kernel linux-2.6.11 through linux-7.2 and related stable branches

Timeline

  • 2026-09-17: disclosed: CVE-2026-90118 published
  • 2026-08-20: patched: Fix committed to Linux kernel stable tree

References

Related threats