CVE-2026-89781
CVE CVE-2026-89781EUVD EUVD-2026-80302Published 2026-09-16T08:48:20.000ZLast changed 2026-09-16T14:38:32.000ZCVSS 8.4
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() read_log_rec_buf() copies a log record into a caller buffer starting at u32 off = lsn_to_page_off(log, lsn) + log->record_header_len; log->record_header_len (and log->data_off, used for the following pages) comes verbatim from the on-disk restart area and is only checked for 8-byte alignment in is_rst_area_valid(), so off can exceed log->page_size. "tail = log->page_size - off" then underflows and memcpy() reads past the page_size-sized buffer returned by read_log_page(), spilling adjacent slab memory into the replay buffer. This is reachable by mounting a crafted NTFS image: BUG: KASAN: slab-out-of-bounds in read_log_rec_buf+0x216/0x580 Read of size 64 at addr ffff88800a877ff8 by task exploit/127 read_log_rec_buf fs/ntfs3/fslog.c:2299 log_replay fs/ntfs3/fslog.c:4216 ntfs_loadlog_and_replay fs/ntfs3/fsntfs.c:324 ntfs_fill_super fs/ntfs3/super.c:1392 get_tree_bdev_flags fs/super.c:1694 __x64_sys_mount fs/namespace.c:4360 The buggy address is located 4088 bytes to the right of the 4096-byte region [ffff88800a876000, ffff88800a877000) Reject an in-page offset outside the current page before the copy. [almaz.alexandrovich@paragon-software.com: replaced the >= sign with >]
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.18.52; patch: 6.6.157; patch: 5.15.221; b46acd6a6a627d876898e1c84d3f84902264b445 <49f7cbc902b08b56eb7d2633163ecc57a0e7145a; patch: 7.2.6; b46acd6a6a627d876898e1c84d3f84902264b445 <53e56f7aa1d0f950a8bc2e4cdb3ba9fe45967531; b46acd6a6a627d876898e1c84d3f84902264b445 <74a83aa05f73033af719771ab1f0c269928b4865; patch: 6.1.188; b46acd6a6a627d876898e1c84d3f84902264b445 <df099bfdb57773ba7f40f8a9dcc82e75af277922; b46acd6a6a627d876898e1c84d3f84902264b445 <de603b9d377fab57a5e6432fa84a9f36b32c1636; patch: 6.12.110; patch: 7.3-rc1; patch: 0; b46acd6a6a627d876898e1c84d3f84902264b445 <700973cc65db405bde0368ccf88699390150943e; b46acd6a6a627d876898e1c84d3f84902264b445 <1b2d31f1083beb80c55d1152249f652c1445a559; 5.15
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.