KernelScan.io

CRITICAL Introduced in 7.1

ntfs MftLcn OOB

CVE-2026-89612

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.8HIGH

01

In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid MFT LCNs from boot sector The NTFS boot sector stores the MFT and MFTMirr locations as unsigned 64-bit LCNs, but parse_ntfs_boot_sector() decoded them into an s64. A crafted high-bit value could therefore become negative and pass the existing upper-bound check. The invalid value then propagated into the MFT zone allocator and could result in an out-of-bounds access to lcn_empty_bits_per_page.

02

Engine v0.6.0

Risk summary

A crafted NTFS filesystem image with a malicious boot sector can bypass cluster-number validation and cause an out-of-bounds memory access in the kernel's MFT zone allocator. The bug is triggered at mount time and requires mounting attacker-controlled media. Impact ranges from kernel panic to memory corruption with potential for code execution.

Affectedfs/ntfs/super.c (NTFS filesystem)

Vulnerability analysis

The NTFS boot sector parser treated cluster location values as signed rather than unsigned numbers. A crafted filesystem image with certain high values in these fields would produce values that slipped past the existing boundary check, and the invalid cluster number then reached the memory allocator where it caused an out-of-bounds access. The fix changes the parser to use unsigned values and comparisons, so any cluster number at or beyond the volume boundary is correctly rejected at mount time. The vulnerability is triggered by mounting a crafted NTFS filesystem image. The most practical attack vector is physical: inserting a USB drive or SD card with a malicious boot sector into a device that auto-mounts removable media.

03

BranchIntroducedFixed inPatch commit
7.27.17.2.48f8420b68a6f
mainline7.17.3-rc1cc9d09fef784