7.8

CVE-2026-89617

fs/ntfs3: validate dirty page table on log replay

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: validate dirty page table on log replay

Each DIR_PAGE_ENTRY ends in a page_lcns[] array whose length is the on-disk
lcns_follow field. check_rstbl() validates the table bookkeeping but never
checks that this array fits in the entry, so a crafted lcns_follow lets the
v0->v1 conversion memmove and later replay passes run off the entry.

Add check_dp_table() to reject, right after check_rstbl(), any entry larger
than its size claims via struct_size() (the same expression used to allocate
these entries, so the check is overflow-safe by construction). All consumers
can then trust lcns_follow as the real capacity. This covers every
page_lcns[] access whose index is bounded by the entry itself (the
conversion memmove, the HotFix store via find_dp(), and the self-bounded
scan loops). Accesses whose index comes from the log record need a separate
bound and are handled in a follow-up patch.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b46acd6a6a627d876898e1c84d3f84902264b445
Version < 0e07ea2fc45a7b4757ef7bf1f692cc0180a08323
Status affected
Version b46acd6a6a627d876898e1c84d3f84902264b445
Version < 1e90b1703ee1a04cd3e9e399353fc536f5f3ba10
Status affected
Version b46acd6a6a627d876898e1c84d3f84902264b445
Version < d23155634a4bc1183e761d5eb2c043b2e693cc98
Status affected
Version b46acd6a6a627d876898e1c84d3f84902264b445
Version < 1200c2779c43b62656ccbb67df9468a7a9af2484
Status affected
Version b46acd6a6a627d876898e1c84d3f84902264b445
Version < 2d94ffc9d7b5bb3517b129fe63b52d84bcd4ae56
Status affected
Version b46acd6a6a627d876898e1c84d3f84902264b445
Version < 0908da07c23be4f94b99dfd9a94765525f0fe4bd
Status affected
Version b46acd6a6a627d876898e1c84d3f84902264b445
Version < 006cb7713dec10368e699abc4367e5faa334c9a5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.035
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1200c2779c43b62656ccbb67df9468a7a9af2484
https://git.kernel.org/stable/c/2d94ffc9d7b5bb3517b129fe63b52d84bcd4ae56
https://git.kernel.org/stable/c/0908da07c23be4f94b99dfd9a94765525f0fe4bd
https://git.kernel.org/stable/c/006cb7713dec10368e699abc4367e5faa334c9a5
https://git.kernel.org/stable/c/0e07ea2fc45a7b4757ef7bf1f692cc0180a08323
https://git.kernel.org/stable/c/1e90b1703ee1a04cd3e9e399353fc536f5f3ba10
https://git.kernel.org/stable/c/d23155634a4bc1183e761d5eb2c043b2e693cc98