KernelScan.io

HIGH Introduced in 7.1

ntfs Decompressor Overflow

CVE-2026-90118

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

KernelScan AI6.7MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one page overflow in ntfs_decompress() The per-token range check in ntfs_decompress() uses if (cb >= cb_sb_end || dp_addr > dp_sb_end) break; so dp_addr == dp_sb_end falls through to the symbol copy `*dp_addr++ = *cb++`, writing one byte past the destination page. Since NTFS_SB_SIZE == PAGE_SIZE the destination is a single page, so the byte lands in the adjacent page, and *dest_ofs is left one past the sub-block end (the later `*dest_ofs &= ~PAGE_MASK` then yields 1, not 0, so the page is never finalized and later sub-blocks keep writing further past it). A corrupted compressed $DATA attribute thus produces a bounded run of out-of-bounds writes when the file is read. Break as soon as dp_addr reaches dp_sb_end; a full sub-block still completes, as its final copy advances dp_addr to exactly dp_sb_end.

02

Engine v0.6.0

Risk summary

An off-by-one error in the NTFS decompression logic allows a corrupted compressed $DATA attribute to trigger a bounded run of out-of-bounds writes past the destination page buffer when the file is read. This can be triggered when a crafted NTFS filesystem is mounted and read, potentially leading to kernel memory corruption, privilege escalation, or a system crash.

Affectedfs/ntfs/compress.c (ntfs)

Vulnerability analysis

The NTFS decompression routine writes one byte past the end of its output page when handling a malformed compressed file. Because the overrun is not detected, subsequent writes continue past the intended page, corrupting adjacent kernel memory. The fix ensures the copy loop stops as soon as the output buffer is full rather than allowing the overflow. An attacker can trigger this by reading a compressed file from a mounted NTFS filesystem that contains a crafted data attribute.

03

BranchIntroducedFixed inPatch commit
7.27.17.2.6b42644e425fe
mainline7.17.3-rc198716c9fce21