HIGH Introduced in 5.15
ntfs3 RestartTable OOB
CVE-2026-89782
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI6.7MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject restart table growth beyond U16_MAX entries During $LogFile replay, log_replay() indexes the transaction table by the transact_id taken from the log record header. check_log_rec() only verifies that transact_id is non-zero and properly aligned, not its magnitude, so a crafted image can request an arbitrarily large index. alloc_rsttbl_from_idx() grows the table to cover that index via extend_rsttbl(), which passes the new entry count to init_rsttbl(): rt = init_rsttbl(esize, used + add); used + add is computed as u32 but init_rsttbl() takes a u16, and the count is stored in struct RESTART_TABLE as a __le16. When used + add exceeds U16_MAX it is truncated, init_rsttbl() allocates a table far smaller than the index requires, and alloc_rsttbl_from_idx() then dereferences and writes at the original, untruncated offset -- an out-of-bounds access past the allocation, reachable by mounting a crafted NTFS image. BUG: KASAN: use-after-free in alloc_rsttbl_from_idx (fs/ntfs3/fslog.c:950) Read of size 4 at addr ffff8880327ffff8 by task exploit alloc_rsttbl_from_idx (fs/ntfs3/fslog.c:950) log_replay (fs/ntfs3/fslog.c:4562) ntfs_loadlog_and_replay (fs/ntfs3/fsntfs.c:324) ntfs_fill_super (fs/ntfs3/super.c:1393) get_tree_bdev_flags vfs_get_tree path_mount __x64_sys_mount A restart table is limited to U16_MAX entries by its __le16 count, so a larger growth request is invalid input. Reject it in extend_rsttbl(); all callers already handle a NULL return.
02KernelScan AI Analysis
Risk summary
A crafted NTFS filesystem image can trigger an out-of-bounds memory access during journal replay at mount time, leading to kernel heap corruption. Exploitation requires the ability to mount an NTFS image, which needs real CAP_SYS_ADMIN in the init namespace. The impact includes potential kernel code execution, information disclosure, or a system crash.
Vulnerability analysis
When the NTFS3 driver replays the journal ($LogFile) during mount, it grows an internal restart table to cover an index taken from the log record header. The table entry count is computed as a 32-bit value but stored in a 16-bit field, so when a crafted image requests an index that pushes the count past 65535 the value is silently truncated. The table is then allocated far smaller than the index requires, and subsequent accesses at the original large offset land out of bounds past the buffer — corrupting kernel heap memory. The fix rejects any growth request that would exceed the 16-bit entry limit, returning an error that the existing callers already handle. The vulnerable path is reached only by mounting a crafted NTFS filesystem image, which requires real CAP_SYS_ADMIN in the init namespace (ntfs3 cannot be mounted inside user namespaces), so the realistic attacker is a privileged local user or a compromised privileged service that performs filesystem mounts.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.1 | 5.15 | 6.1.188 | 339e59996ff1 |
| 7.2 | 5.15 | 7.2.6 | 967a5ff8a614 |
| mainline | 5.15 | 7.3-rc1 | 111f8d74a19d |
| 6.12 | 5.15 | 6.12.110 | be218a01aadf |
| 5.15 | 5.15 | 5.15.221 | caa0ec3fc44a |
| 6.6 | 5.15 | 6.6.157 | ecde45cd81dc |
| 6.18 | 5.15 | 6.18.52 | aad605a45061 |