Out-of-Bounds Read Vulnerability in Linux Kernel's NTFS3 by Paragon Software
CVE-2026-89781
What is CVE-2026-89781?
A vulnerability in the Linux kernel's NTFS3 implementation could allow an attacker to exploit out-of-bounds memory access. Specifically, the issue arises in the read_log_rec_buf() function, where the calculation for the offset of a log record may exceed the allocated buffer size. This can happen when a crafted NTFS image is mounted, potentially allowing the attacker to read beyond the buffer limits and access adjacent memory. To mitigate this risk, it is essential for users to update to patched versions that reject improper in-page offsets before executing the copy action.
Affected Version(s)
Linux b46acd6a6a627d876898e1c84d3f84902264b445
Linux b46acd6a6a627d876898e1c84d3f84902264b445 < 1b2d31f1083beb80c55d1152249f652c1445a559
Linux b46acd6a6a627d876898e1c84d3f84902264b445 < 700973cc65db405bde0368ccf88699390150943e