Out-of-Bounds Read Vulnerability in Linux Kernel NTFS Handling
CVE-2026-80869

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80869?

A vulnerability in the Linux kernel's NTFS file system allows for an out-of-bounds read during the processing of attribute lists. Specifically, the validation checks in the 'ntfs_read_inode_mount()' function are insufficient, enabling crafted $MFT entries to bypass security measures. When these entries are processed, they can lead to memory access violations, potentially exposing sensitive data or causing system crashes. The issue arises when the attribute length is manipulated, allowing an attacker to exploit the kernel's memory management routines. A patch has been implemented to ensure robust validation of attribute entries, significantly enhancing the security of NTFS handling within the Linux kernel.

Affected Version(s)

Linux 1e9ea7e04472d4e5e12e58c881eaacfb3e49b669

Linux 1e9ea7e04472d4e5e12e58c881eaacfb3e49b669 < 98634df5b1cb56c26299b7409227025ddb0167d8

Linux 7.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.