-

CVE-2026-90117

ntfs: validate usa_ofs before preserving the update sequence number

In the Linux kernel, the following vulnerability has been resolved:

ntfs: validate usa_ofs before preserving the update sequence number

When ntfs_mft_record_alloc() reuses a free mft record it reads the old
update sequence number straight from the on-disk record:

     usn = *(__le16 *)((u8 *)m + le16_to_cpu(m->usa_ofs));

Here m points into the raw $MFT page-cache folio, which still holds
unvalidated, MST-protected bytes: the folio is read by a plain
iomap_read_folio() and neither post_read_mst_fixup() nor
ntfs_mft_record_check() has run on it (both work on private copies).
m->usa_ofs is therefore an untrusted u16, and a corrupted record can put
it past the end of the record so the two-byte read lands outside the
folio.  Reading such a record while creating a file gives, under KASAN:

   BUG: KASAN: use-after-free in ntfs_mft_record_alloc+...
   Read of size 2 at addr ...
    ntfs_mft_record_alloc -> __ntfs_create -> ntfs_create -> path_openat

Only preserve the old update sequence number when usa_ofs is even and in
range, mirroring the check ntfs_mft_record_check() already applies;
otherwise leave usn zero, which the existing restore below skips.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 495e90fa334828d4119061e2726af51d0a0fb4ed
Version < ea5a3c30710710c1dc5e483d3313309ec2e868f7
Status affected
Version 495e90fa334828d4119061e2726af51d0a0fb4ed
Version < 81684340963da2e898eabb8c1e274433d9375bc6
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 7.1
Status affected
Version 0
Version < 7.1
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ea5a3c30710710c1dc5e483d3313309ec2e868f7
https://git.kernel.org/stable/c/81684340963da2e898eabb8c1e274433d9375bc6