KernelScan.io

CRITICAL Introduced in 7.1

ntfs MappingPairs Corruption

CVE-2026-89613

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI6.7MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid empty mapping pairs Reject an attribute with empty mapping pairs if it has inconsistent highest VCN and size.

02

Engine v0.6.0

Risk summary

A crafted NTFS filesystem image with invalid empty mapping pairs can trigger memory corruption or a kernel crash when mounted. The vulnerability requires root-level privileges to trigger via manual mounting, but systems with automount enabled are also exposed via physical access to removable media. Any product that can mount attacker-supplied NTFS images is at risk.

Affectedfs/ntfs/runlist.c (ntfs filesystem driver)

Vulnerability analysis

A crafted NTFS filesystem image can contain attributes with empty mapping pairs that claim non-zero sizes, which the driver fails to reject before attempting to decompress them. Processing these invalid attributes can corrupt memory or crash the kernel. The fix adds a validation step that rejects attributes whose empty mapping pairs are inconsistent with their declared size and extent information, returning an I/O error instead of proceeding. This vulnerability is reachable by mounting a malicious NTFS image, which requires root-level privileges since NTFS cannot be mounted from unprivileged user namespaces. Systems with automount enabled are also exposed to physical attacks via removable media.

03

BranchIntroducedFixed inPatch commit
7.27.17.2.4b0cc6dbc655e
mainline7.17.3-rc1766062a82e1c