Linux Kernel Vulnerability Affects NTFS3 from Paragon Software
CVE-2026-63833

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63833?

A vulnerability has been identified in the NTFS3 component of the Linux kernel, allowing unprivileged users to write directly to reserved extended attributes ($LXUID, $LXGID, $LXMOD, and $LXDEV). This can lead to unauthorized elevation of privileges, as a malicious actor could manipulate file ownership and permissions on a writable NTFS3 mount, thereby executing code with elevated privileges. Internal metadata updates remain secure since they utilize controlled methods. The vulnerability has been addressed by enforcing restrictions on direct user writes to the specified metadata attributes.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2c3cd6da4a14380ef79e34bd9dff7caf46687477

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.