HIGH
ntfs3 VcnValidation Bypass
CVE-2026-90199
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
KernelScan AI6.0MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject out-of-range evcn in mi_enum_attr() In mi_enum_attr(), the start/end VCN validation for non-resident attributes is: if (svcn > evcn + 1) goto out; When evcn is U64_MAX the "evcn + 1" expression wraps to 0 and any svcn passes the check. For evcn values close to U64_MAX (but not equal to it) the right-hand side is still a meaningless near-wrap upper bound, so a malformed on-disk attribute with svcn == 0 and evcn near U64_MAX can pass mi_enum_attr() unrejected. VCN (virtual cluster number) is a cluster index, so any valid evcn is bounded by the volume's total cluster count, which ntfs3 holds in sbi->used.bitmap.nbits (set up in ntfs_init_from_boot() before any caller of mi_enum_attr() runs). Reject evcn values that fall outside this range. However, an empty non-resident attribute (no allocated clusters) is legitimately encoded with svcn == 0 and evcn == -1 (U64_MAX), e.g. via attr->nres.evcn = cpu_to_le64((u64)vcn - 1) with vcn == 0. That sentinel must keep passing, so exclude evcn == U64_MAX from the range check. The existing "svcn > evcn + 1" test still tolerates the sentinel ("0 > 0" is false) and continues to require svcn == 0 for it, while the range check rejects every other out-of-range evcn and thereby also defuses the "evcn + 1" wraparound. svcn does not need its own bound: once evcn < nbits, "svcn > evcn + 1" implies svcn <= nbits. [almaz.alexandrovich@paragon-software.com: fixed evcn check]
02KernelScan AI Analysis
Risk summary
A malformed NTFS3 filesystem image with an out-of-range end VCN in a non-resident attribute can bypass validation in the attribute enumeration routine due to an integer wraparound in the bounds check. An attacker who can mount a crafted NTFS volume can trigger kernel memory corruption or a denial of service.
Vulnerability analysis
The attribute enumeration routine validates non-resident attribute VCN ranges with a comparison that wraps around when the end VCN is near the maximum 64-bit value, allowing a malformed on-disk attribute to pass unchecked. The fix bounds the end VCN against the volume's total cluster count while preserving the legitimate empty-attribute sentinel, closing the wraparound path. The vulnerable code is reached when the ntfs3 driver parses a mounted filesystem image, so an attacker must supply a crafted NTFS volume and have it mounted by a privileged user or via removable media.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.15 | 5.15.209 | 5.16 | 0441e34ce098 |
| 6.1 | 6.1.115 | 6.2 | 7ab69cef49eb |
| 6.6 | — | 6.6.157 | 2b9a0e57bfd3 |
| 6.12 | — | 6.12.110 | 20fd9f64c005 |
| 6.18 | — | 6.18.52 | — |
| 7.2 | — | 7.2.6 | — |
| mainline | — | 7.3-rc1 | — |
| 6.5 | 6.5.11 | 6.6 | ce9a619c432b |