Out-of-bounds Read Vulnerability in Linux Kernel NTFS3 by Linux Foundation
CVE-2026-89785

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-89785?

A vulnerability exists in the Linux Kernel NTFS3 module that allows an out-of-bounds read when parsing index root attributes of the $Extend/$Reparse and $Extend/$ObjId metafiles. This occurs due to insufficient checks leading to potential reads beyond allocated memory, which can compromise data integrity while mounting specially crafted NTFS images. To mitigate this risk, system administrative privileges (CAP_SYS_ADMIN) are required, emphasizing the importance of careful usage of mounts.

Affected Version(s)

Linux 82cae269cfa953032fbb8980a7d554d60fb00b17

Linux 82cae269cfa953032fbb8980a7d554d60fb00b17

Linux 82cae269cfa953032fbb8980a7d554d60fb00b17 < 94fce1d3e74fe011e21f17490ba58491709fd7e5

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.