Linux Kernel NTFS Cluster Management Vulnerability
CVE-2026-98139
What is CVE-2026-98139?
In the Linux kernel, a vulnerability has been identified in the NTFS support that affects how cluster management is handled. Specifically, the ntfs_cluster_free_from_rl_nolock() function inaccurately tallies successfully freed cluster runs. If the bitmap clearing process fails, the function continues to count the run’s length, leading to misrepresented free cluster counts. This miscalculation can corrupt the allocator's free space tracking and produce incorrect statistics when querying the file system state, impacting system stability and performance. Applying appropriate updates is essential to resolve this vulnerability and maintain system integrity.
Affected Version(s)
Linux 11ccc9107dc460de28af90fac1f42404d9802735 < 7eb97d8828e7758b9c81277f7802e740a800f78a
Linux 11ccc9107dc460de28af90fac1f42404d9802735
Linux 7.1