KernelScan.io

HIGH Introduced in 5.15

ntfs3 LogRecord OOB

CVE-2026-89781

CVSS 8.4 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI5.8MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() read_log_rec_buf() copies a log record into a caller buffer starting at u32 off = lsn_to_page_off(log, lsn) + log->record_header_len; log->record_header_len (and log->data_off, used for the following pages) comes verbatim from the on-disk restart area and is only checked for 8-byte alignment in is_rst_area_valid(), so off can exceed log->page_size. "tail = log->page_size - off" then underflows and memcpy() reads past the page_size-sized buffer returned by read_log_page(), spilling adjacent slab memory into the replay buffer. This is reachable by mounting a crafted NTFS image: BUG: KASAN: slab-out-of-bounds in read_log_rec_buf+0x216/0x580 Read of size 64 at addr ffff88800a877ff8 by task exploit/127 read_log_rec_buf fs/ntfs3/fslog.c:2299 log_replay fs/ntfs3/fslog.c:4216 ntfs_loadlog_and_replay fs/ntfs3/fsntfs.c:324 ntfs_fill_super fs/ntfs3/super.c:1392 get_tree_bdev_flags fs/super.c:1694 __x64_sys_mount fs/namespace.c:4360 The buggy address is located 4088 bytes to the right of the 4096-byte region [ffff88800a876000, ffff88800a877000) Reject an in-page offset outside the current page before the copy. [almaz.alexandrovich@paragon-software.com: replaced the >= sign with >]

02

Engine v0.6.0

Risk summary

Mounting a crafted NTFS3 image triggers an out-of-bounds slab read in the log replay path, leaking adjacent kernel heap memory and potentially crashing the kernel. The bug is reachable by any actor who can cause a crafted NTFS image to be mounted, such as via removable media or a privileged actor mounting attacker-supplied data. Impact is denial of service and disclosure of kernel memory.

Affectedfs/ntfs3/fslog.c (ntfs3 filesystem)

Vulnerability analysis

When the ntfs3 driver replays a filesystem journal, it computes an in-page copy offset from values stored verbatim in the on-disk restart area. A crafted image can make that offset exceed the page size, causing a subtraction to underflow and a subsequent copy to read past the end of a page-sized slab buffer, spilling adjacent kernel heap memory into the replay buffer. The fix rejects any offset that lies outside the current page before the copy proceeds. The vulnerable path is reached by mounting a crafted NTFS image, which requires either physical access to a removable-media port or a privileged actor who can run mount against attacker-supplied data.

03

BranchIntroducedFixed inPatch commit
6.15.156.1.1881b2d31f1083b
6.65.156.6.157700973cc65db
6.185.156.18.5274a83aa05f73
7.25.157.2.653e56f7aa1d0
5.155.155.15.221df099bfdb577
mainline5.157.3-rc1de603b9d377f
6.125.156.12.11049f7cbc902b0