CRITICAL Introduced in 7.1
ntfs MappingPairs Corruption
CVE-2026-89613
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI6.7MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid empty mapping pairs Reject an attribute with empty mapping pairs if it has inconsistent highest VCN and size.
02KernelScan AI Analysis
Risk summary
A crafted NTFS filesystem image with invalid empty mapping pairs can trigger memory corruption or a kernel crash when mounted. The vulnerability requires root-level privileges to trigger via manual mounting, but systems with automount enabled are also exposed via physical access to removable media. Any product that can mount attacker-supplied NTFS images is at risk.
Vulnerability analysis
A crafted NTFS filesystem image can contain attributes with empty mapping pairs that claim non-zero sizes, which the driver fails to reject before attempting to decompress them. Processing these invalid attributes can corrupt memory or crash the kernel. The fix adds a validation step that rejects attributes whose empty mapping pairs are inconsistent with their declared size and extent information, returning an I/O error instead of proceeding. This vulnerability is reachable by mounting a malicious NTFS image, which requires root-level privileges since NTFS cannot be mounted from unprivileged user namespaces. Systems with automount enabled are also exposed to physical attacks via removable media.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 7.2 | 7.1 | 7.2.4 | b0cc6dbc655e |
| mainline | 7.1 | 7.3-rc1 | 766062a82e1c |