Memory Leak Vulnerability in Linux Kernel's NTFS3 Filesystem Handling
CVE-2026-89779

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-89779?

A vulnerability exists in the Linux kernel's NTFS3 filesystem handling, where insufficient validation of extended attribute (EA) records can be exploited. When an EA record specifies a non-zero size, the kernel only verifies that the size fits within the buffer, neglecting to ensure that the size is adequate to hold the entire record, including its name and value lengths. This oversight allows attackers to craft a malicious image that can bypass safeguards. Upon exploitation, it results in an out-of-bounds memory read, enabling sensitive data leakage from the heap memory to userspace. This vulnerability highlights the critical importance of thorough validation in file system operations.

Affected Version(s)

Linux 333feb7ba84f69f9b423422417aaac54fd9e7c84

Linux 000a9a72efa4a9df289bab9c9e8ba1639c72e0d6 < 28a924c7e67e6d71abeb04860b61166fecb027fc

Linux 0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.