7.5

CVE-2026-89616

fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()

ni_read_frame() decompresses an LZNT $DATA frame into the vmapped target
pages and then trusts decompress_lznt()'s return value:

  unc_size = decompress_lznt(frame_ondisk, ondisk_size, frame_mem,
                             frame_size);
  if ((ssize_t)unc_size < 0)        err = unc_size;
  else if (!unc_size || unc_size > frame_size)  err = -EINVAL;

decompress_lznt() stops as soon as the compressed stream is exhausted
(e.g. a zero chunk header) and returns the number of bytes it actually
wrote, which may be far less than frame_size. The bytes between unc_size
and frame_size are never written. The only memset() that follows zeroes
the region beyond i_valid; when the frame lies entirely within the file's
valid size that memset() does not run, so the gap retains whatever was in
the just-vmapped pages. All pages are then marked uptodate and returned
to userspace, disclosing uninitialized (recently-freed) kernel page
memory. A crafted compressed file whose stream decompresses to only a few
bytes leaks the remainder of every frame on a plain read(2), which is
enough to recover kernel pointers and defeat KASLR.

Zero the [unc_size, frame_size) tail immediately after a successful LZNT
decompress so the remainder reads back as zero.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4342306f0f0d5ff4315a204d315c1b51b914fca5
Version < 7d60a4c49af4d5cb88aa7cbf998d0408bd415055
Status affected
Version 4342306f0f0d5ff4315a204d315c1b51b914fca5
Version < cd40eee4923d104ebec9ac7513b971bc441e431d
Status affected
Version 4342306f0f0d5ff4315a204d315c1b51b914fca5
Version < 77d8efd04745cda23858546afdbd9d07b591758e
Status affected
Version 4342306f0f0d5ff4315a204d315c1b51b914fca5
Version < 0f699ddb290a24b37e1bc9bf1e3c9dbccf564bea
Status affected
Version 4342306f0f0d5ff4315a204d315c1b51b914fca5
Version < 376ee45659a4b943df672ad275c63da00655f929
Status affected
Version 4342306f0f0d5ff4315a204d315c1b51b914fca5
Version < 4a1b39b2e10eb8de86265e80cf2be4396bc1dce4
Status affected
Version 4342306f0f0d5ff4315a204d315c1b51b914fca5
Version < 35d1ea92c7d946e2ebdbe36cdb2c969c8704bebd
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.307
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0f699ddb290a24b37e1bc9bf1e3c9dbccf564bea
https://git.kernel.org/stable/c/376ee45659a4b943df672ad275c63da00655f929
https://git.kernel.org/stable/c/4a1b39b2e10eb8de86265e80cf2be4396bc1dce4
https://git.kernel.org/stable/c/35d1ea92c7d946e2ebdbe36cdb2c969c8704bebd
https://git.kernel.org/stable/c/77d8efd04745cda23858546afdbd9d07b591758e
https://git.kernel.org/stable/c/7d60a4c49af4d5cb88aa7cbf998d0408bd415055
https://git.kernel.org/stable/c/cd40eee4923d104ebec9ac7513b971bc441e431d