Executive brief
A race condition in the Linux kernel's NTFS filesystem implementation allows concurrent readers and writers to access file metadata simultaneously without proper synchronization. An attacker could trigger this by repeatedly reading a small NTFS file while concurrently creating and deleting hard links to it, potentially causing the kernel to observe corrupted or inconsistent file attributes that could lead to a crash or data corruption.
Technical details
The vulnerability is a data race (CWE-366) in ntfs_read_iomap_begin_resident() which walks the Master File Table (MFT) record via ntfs_attr_lookup() without holding the ni->mrec_lock mutex, while concurrent operations like ntfs_attr_record_resize() modify the same buffer under the lock. The mmap read fault path can observe torn attribute fields (e.g., bytes_in_use, offset) while unlink()/link() operations relocate records. The attack vector is local and unprivileged; no authentication is required. An attacker can exploit this by concurrently reading a resident NTFS file and performing file operations (link/unlink) to trigger the race, potentially causing kernel memory corruption or a denial of service. The fix serializes the resident read path with mrec_lock and stores the inode reference in iomap->private for deferred lock release in the iomap_end() callback.
Affected products
- Linux Linux kernel versions prior to the fix
Timeline
- 2026-09-17: disclosed