-

CVE-2026-90134

ntfs: fix kmap_local_page() usage in compress

In the Linux kernel, the following vulnerability has been resolved:

ntfs: fix kmap_local_page() usage in compress

Several compressed I/O paths discard the address returned by
kmap_local_page() and later access or unmap the page using page_address().
This is invalid for highmem pages, and local mappings must also be unmapped
using the address returned by kmap_local_page().

Map each destination page in ntfs_decompress() only while producing the
current sub-block. Use memcpy_from_page(), memcpy_to_page(), and
memzero_page() for the other page accesses. Remove unnecessary local
mappings from ntfs_write_cb(), where pages are accessed through the vmap()
mapping.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 495e90fa334828d4119061e2726af51d0a0fb4ed
Version < 950e2ecc7aec21af24b05bc661a097a81c670409
Status affected
Version 495e90fa334828d4119061e2726af51d0a0fb4ed
Version < 6e03fbd5f772ad24ea64f7632e4d0d73184787ca
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 7.1
Status affected
Version 0
Version < 7.1
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.089
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/950e2ecc7aec21af24b05bc661a097a81c670409
https://git.kernel.org/stable/c/6e03fbd5f772ad24ea64f7632e4d0d73184787ca