Buffer Overflow Vulnerability in Linux Kernel NTFS3 by Vendor
CVE-2026-64532

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64532?

A vulnerability has been identified in the Linux Kernel NTFS3 module that could lead to a buffer overflow condition. The issue arises from improper validation of the 'view.data_off' value during the memory operations in the UpdateRecordData functions. Without adequate checks on the data offset against the size of the NTFS Directory Entry (NTFS_DE), a memmove operation could overwrite memory beyond the allocated buffer, potentially allowing for data corruption or undefined behavior. Inline checks have been proposed to mitigate this issue, ensuring that memory operations remain within safe boundaries.

Affected Version(s)

Linux b46acd6a6a627d876898e1c84d3f84902264b445

Linux b46acd6a6a627d876898e1c84d3f84902264b445

Linux b46acd6a6a627d876898e1c84d3f84902264b445 < 429d653ca641d38a78609b8f62e81a0a5c780a2d

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.