-

CVE-2026-97439

fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib

[BUG]
A corrupted ntfs3 image can hit a NULL function pointer call in
generic_perform_write() after toggling system.ntfs_attrib and then
overwriting system.dos_attrib on the same file.

BUG: kernel NULL pointer dereference, address: 0000000000000000
\#PF: supervisor instruction fetch in kernel mode
\#PF: error_code(0x0010) - not-present page
PGD bed5067 P4D bed5067 PUD 0
Oops: Oops: 0010 [#1] SMP KASAN NOPTI
RIP: 0010:0x0
Code: Unable to access opcode bytes at 0xffffffffffffffd6.
RSP: 0018:ffff88801025f988 EFLAGS: 00010246
Call Trace:
 generic_perform_write+0x409/0x8c0 mm/filemap.c:4255
 __generic_file_write_iter+0x1bb/0x200 mm/filemap.c:4372
 ntfs_file_write_iter+0xcd9/0x1c20 fs/ntfs3/file.c:1253
 new_sync_write fs/read_write.c:593 [inline]
 vfs_write+0x63b/0xf70 fs/read_write.c:686
 ksys_write+0x133/0x250 fs/read_write.c:738
 __do_sys_write fs/read_write.c:749 [inline]
 __se_sys_write fs/read_write.c:746 [inline]
 __x64_sys_write+0x77/0xc0 fs/read_write.c:746
 ...

[CAUSE]
system.ntfs_attrib updates ATTR_DATA flags via ni_new_attr_flags()
and switches i_mapping->a_ops to ntfs_aops_cmpr when
FILE_ATTRIBUTE_COMPRESSED is set. system.dos_attrib then overwrites
ni->std_fa from a one-byte DOS attribute value, clearing the compression
bit without updating ATTR_DATA or the mapping operations.

Old buffered writes use is_compressed(ni) to choose
__generic_file_write_iter(). That leaves generic_perform_write() calling
a NULL write_begin callback from ntfs_aops_cmpr.

[FIX]
Treat system.dos_attrib as a low-byte DOS attribute update and preserve the
existing non-DOS attribute bits in ni->std_fa. This keeps compressed and
sparse state consistent with ATTR_DATA and the mapping operations while
keeping the existing DOS attribute semantics intact.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version be71b5cba2e6485e8959da7a9f9a44461a1bb074
Version < 533217b90addd57cc16f1c974e023c72d18949c7
Status affected
Version be71b5cba2e6485e8959da7a9f9a44461a1bb074
Version < f2d6bc89e2236939df189831707c8cdad199f57a
Status affected
Version be71b5cba2e6485e8959da7a9f9a44461a1bb074
Version < fdc9f65aa6631df04238c6154713bacd5133d77c
Status affected
Version be71b5cba2e6485e8959da7a9f9a44461a1bb074
Version < 2de91ae285b0b878604d2bd83c3c395a8071e482
Status affected
Version be71b5cba2e6485e8959da7a9f9a44461a1bb074
Version < 407ee19828a7d9700969ed9cc53be50d0f533619
Status affected
Version be71b5cba2e6485e8959da7a9f9a44461a1bb074
Version < b1c1101067d9536bcb0fe023b96ee2dde5535959
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2de91ae285b0b878604d2bd83c3c395a8071e482
https://git.kernel.org/stable/c/407ee19828a7d9700969ed9cc53be50d0f533619
https://git.kernel.org/stable/c/b1c1101067d9536bcb0fe023b96ee2dde5535959
https://git.kernel.org/stable/c/533217b90addd57cc16f1c974e023c72d18949c7
https://git.kernel.org/stable/c/f2d6bc89e2236939df189831707c8cdad199f57a
https://git.kernel.org/stable/c/fdc9f65aa6631df04238c6154713bacd5133d77c