HIGH Introduced in 7.1
ntfs Decompressor Overflow
CVE-2026-90118
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
KernelScan AI6.7MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one page overflow in ntfs_decompress() The per-token range check in ntfs_decompress() uses if (cb >= cb_sb_end || dp_addr > dp_sb_end) break; so dp_addr == dp_sb_end falls through to the symbol copy `*dp_addr++ = *cb++`, writing one byte past the destination page. Since NTFS_SB_SIZE == PAGE_SIZE the destination is a single page, so the byte lands in the adjacent page, and *dest_ofs is left one past the sub-block end (the later `*dest_ofs &= ~PAGE_MASK` then yields 1, not 0, so the page is never finalized and later sub-blocks keep writing further past it). A corrupted compressed $DATA attribute thus produces a bounded run of out-of-bounds writes when the file is read. Break as soon as dp_addr reaches dp_sb_end; a full sub-block still completes, as its final copy advances dp_addr to exactly dp_sb_end.
02KernelScan AI Analysis
Risk summary
An off-by-one error in the NTFS decompression logic allows a corrupted compressed $DATA attribute to trigger a bounded run of out-of-bounds writes past the destination page buffer when the file is read. This can be triggered when a crafted NTFS filesystem is mounted and read, potentially leading to kernel memory corruption, privilege escalation, or a system crash.
Vulnerability analysis
The NTFS decompression routine writes one byte past the end of its output page when handling a malformed compressed file. Because the overrun is not detected, subsequent writes continue past the intended page, corrupting adjacent kernel memory. The fix ensures the copy loop stops as soon as the output buffer is full rather than allowing the overflow. An attacker can trigger this by reading a compressed file from a mounted NTFS filesystem that contains a crafted data attribute.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 7.2 | 7.1 | 7.2.6 | b42644e425fe |
| mainline | 7.1 | 7.3-rc1 | 98716c9fce21 |