Linux Kernel NTFS Vulnerability in EA Flag Handling
CVE-2026-98133

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98133?

A vulnerability in the Linux kernel's NTFS implementation affects the management of the HasEA flag during extended attribute operations. When attempting to set extended attributes, the kernel incorrectly updates the HasEA flag on failure, thus hiding existing on-disk extended attributes until the inode is cleared. This flaw occurs specifically in the ntfs_set_ea() function, where the update of the HasEA flag should only occur upon successful completion of the operation. Failures in this process can lead to data concealment and unexpected behavior in file handling.

Affected Version(s)

Linux fc053f05ca282a5e760b41f6560ac835c4e28037 < 5811a08310754cbf4a1122c81d14c54b8873c35c

Linux fc053f05ca282a5e760b41f6560ac835c4e28037

Linux 7.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.