Linux Kernel Boot Sector Vulnerability in NTFS by Linux Foundation
CVE-2026-98135

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98135?

A vulnerability exists in the Linux NTFS implementation where the 'sectors_per_cluster' field in the boot sector can be improperly validated. This issue occurs when non-standard values or zero are accepted instead of rejecting them. This can lead to undefined behavior, particularly when the system attempts to shift bits using an incorrect shift exponent, which may lead to potential exploitation avenues. The patch introduced ensures that only power-of-two values are accepted for 'sectors_per_cluster', enhancing the robustness of the system.

Affected Version(s)

Linux 6251f0b0de7d645e3591931ca4c11d8322c1866f < 7524c3145a3bac92bebbc47a29c007f1d874c9b3

Linux 6251f0b0de7d645e3591931ca4c11d8322c1866f < 323751a604e7533fa473874d999371592a614207

Linux 7.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.