← All Advisories

Linux Kernel NTFS attrdef Parser Reads Past a Short Attribute-Definition Table, Triggering Out-of-Bounds Access

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-98136

Key Details

CVECVE-2026-98136
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-10-08
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsLinux Kernel
Classified asCWE-125 (Out-of-bounds Read)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ntfs: bound $AttrDef table walk to the loaded table size

ntfs_attr_find_in_attrdef() walks the in-memory $AttrDef table, but the

loop condition bounds only the start of each entry, not the whole entry:

for (ad = vol->attrdef; (u8 *)ad - (u8 *)vol->attrdef <

vol->attrdef_size && ad->type; ++ad)

struct attr_def is 160 bytes; the guard reads ad->type at offset 128 and

the loop body reads further fields. vol->attrdef is kvzalloc(i_size),

where i_size is the on-disk $AttrDef data size, checked in

load_and_init_attrdef() only as 0 < i_size <= 0x7fffffff. A volume whose

$AttrDef data size is smaller than one entry (e.g. 120 bytes) makes the

read of ad->type run past the allocation. Creating a file reaches this

through ntfs_attr_size_bounds_check() and reads out of bounds:

BUG: KASAN: slab-out-of-bounds in ntfs_attr_find_in_attrdef+0x66/0xa0

Read of size 4 at addr ffff888005833280 by task init/1

ntfs_attr_find_in_attrdef

ntfs_attr_size_bounds_check

ntfs_attr_can_be_non_resident

ntfs_attr_add

Require the whole entry to lie within attrdef_size in the loop guard, and

reject at mount a $AttrDef too small to hold one attr_def entry. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98136
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98136