Out-of-Bounds Read Vulnerability in Linux Kernel's NTFS3 by Paragon Software
CVE-2026-89781

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-89781?

A vulnerability in the Linux kernel's NTFS3 implementation could allow an attacker to exploit out-of-bounds memory access. Specifically, the issue arises in the read_log_rec_buf() function, where the calculation for the offset of a log record may exceed the allocated buffer size. This can happen when a crafted NTFS image is mounted, potentially allowing the attacker to read beyond the buffer limits and access adjacent memory. To mitigate this risk, it is essential for users to update to patched versions that reject improper in-page offsets before executing the copy action.

Affected Version(s)

Linux b46acd6a6a627d876898e1c84d3f84902264b445

Linux b46acd6a6a627d876898e1c84d3f84902264b445 < 1b2d31f1083beb80c55d1152249f652c1445a559

Linux b46acd6a6a627d876898e1c84d3f84902264b445 < 700973cc65db405bde0368ccf88699390150943e

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.