Linux Kernel NTFS Vulnerability – Volume Management Issue
CVE-2026-98138

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98138?

A vulnerability in the Linux kernel's NTFS driver allows for improper handling of volume status during the sync process. Specifically, when errors are encountered on an NTFS volume, the system incorrectly clears the 'dirty bit' β€” which is intended to indicate volume integrity issues. This flaw can lead to a situation where a volume that has recorded errors is mistakenly marked as clean, thereby preventing necessary recovery procedures. The change implemented ensures that the 'dirty bit' remains set when volume errors are present, thereby enhancing data integrity management and ensuring volumes requiring recovery are appropriately flagged.

Affected Version(s)

Linux 6251f0b0de7d645e3591931ca4c11d8322c1866f

Linux 6251f0b0de7d645e3591931ca4c11d8322c1866f < 0e4c839905418d55bafe571a92533a1d1ac7b0a8

Linux 7.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.