KernelScan.io

CRITICAL Introduced in 2.6.12

ntfs RunLength OOB

CVE-2026-89610

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI6.7MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: ntfs: verify run length exceeding volume boundary The mapping pairs decoder validates that the starting LCN is within the volume but does not check if the run extends beyond the volume boundary. A malformed NTFS image with a crafted mapping pairs array could cause the kernel to access memory beyond the volume boundary, potentially leading to memory corruption and privilege escalation. Add validation to ensure lcn + length stays within nr_clusters.

02

Engine v0.6.0

Risk summary

A malformed NTFS filesystem image can trick the kernel into accessing memory beyond the volume boundary because the mapping pairs decoder only validates the starting cluster position, not the full run length. This can lead to kernel memory corruption and potential privilege escalation. The vulnerability is reachable whenever a crafted NTFS image is mounted, requiring either root privileges or physical access to removable media that triggers auto-mount.

Affectedfs/ntfs/runlist.c (ntfs filesystem)

Vulnerability analysis

The NTFS mapping pairs decoder validates that the starting cluster number of a data run falls within the volume but never checks whether the run extends past the volume boundary. A crafted NTFS image can specify a valid starting position with an oversized run length, causing the kernel to access memory beyond the allocated volume space and corrupt kernel memory. The fix adds an overflow-safe bounds check ensuring the run's end position (starting cluster plus length) does not exceed the total cluster count of the volume, rejecting the malformed image if it does. Triggering this requires mounting a crafted NTFS filesystem image, which needs CAP_SYS_ADMIN in the init namespace or physical access to insert removable media that is auto-mounted by the system.

03

BranchIntroducedFixed inPatch commit
7.22.6.127.2.46e844d4b8243
mainline2.6.127.3-rc1fea9e4488f38