7.1

CVE-2026-97437

ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e()

In the Linux kernel, the following vulnerability has been resolved:

ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e()

The bounds check in ntfs_dir_emit() compares fname->name_len (a
character count) against e->size (a byte count) without accounting
for the 2-byte-per-character UTF-16LE encoding or the ATTR_FILE_NAME
header size:

  if (fname->name_len + sizeof(struct NTFS_DE) > le16_to_cpu(e->size))

This computes: name_len + 16 > e_size

The correct check must account for the ATTR_FILE_NAME header (66 bytes
before the name) and the UTF-16LE character size (2 bytes each):

  sizeof(NTFS_DE) + offsetof(ATTR_FILE_NAME, name) +
  name_len * sizeof(short) > e_size

Which computes: 16 + 66 + name_len * 2 > e_size

The correct calculation already exists as fname_full_size() in ntfs.h
and is used in cmp_fnames(), namei.c, and fslog.c, but was not used
in the readdir path.

A crafted NTFS image with an index entry containing a small e->size
but large fname->name_len bypasses the current check, causing
ntfs_utf16_to_nls() to read past the entry boundary.

Additionally, add a key_size validation in hdr_find_e() to ensure the
declared key_size does not exceed the available entry data, preventing
comparison functions from reading past entry boundaries on the lookup
path.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4342306f0f0d5ff4315a204d315c1b51b914fca5
Version < d1f98938e437732c0ecdfc8ee451e12a072f6d07
Status affected
Version 4342306f0f0d5ff4315a204d315c1b51b914fca5
Version < 0505f1e7bb5b981b6ed62d98b26ddce76142865d
Status affected
Version 4342306f0f0d5ff4315a204d315c1b51b914fca5
Version < 2f7d0ec8c10dc7bf7a8c9a9cb169f9a4d1fac2ba
Status affected
Version 4342306f0f0d5ff4315a204d315c1b51b914fca5
Version < ed6da1abeec50db9060d714f03743fe0b63e4fe4
Status affected
Version 4342306f0f0d5ff4315a204d315c1b51b914fca5
Version < 6a8149a20e46086c756c2a9202e377c0b649a0c3
Status affected
Version 4342306f0f0d5ff4315a204d315c1b51b914fca5
Version < aa1bdbb39f49c5bc9779316891c40005517842a5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.026
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ed6da1abeec50db9060d714f03743fe0b63e4fe4
https://git.kernel.org/stable/c/6a8149a20e46086c756c2a9202e377c0b649a0c3
https://git.kernel.org/stable/c/aa1bdbb39f49c5bc9779316891c40005517842a5
https://git.kernel.org/stable/c/0505f1e7bb5b981b6ed62d98b26ddce76142865d
https://git.kernel.org/stable/c/2f7d0ec8c10dc7bf7a8c9a9cb169f9a4d1fac2ba
https://git.kernel.org/stable/c/d1f98938e437732c0ecdfc8ee451e12a072f6d07