kernel: ntfs: verify run length exceeding volume boundary

cve CVE-2026-89610 2 sources, 2 claims · Watch

Red Hat writes:
kernel: ntfs: verify run length exceeding volume boundary the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectslinux/linux
NVD says “Linux · Linux”
made_bylinux
NVD says “Linux”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
conflict
NVD9.8
receipt
Source
NVD
Its words
9.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "fs/ntfs/runlist.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "6e844d4b82434a781b80d02145fd1b17cf90e3c3",
                "status": "affected",
                "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                "versionType": "git"
              },
              {
                "lessThan": "fea9e4488f384c0ef1c0e3d96b565127c1b98447",
                "status": "affected",
                "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                "versionType": "git"
              },
              {
                "lessThan": "7.2.4",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "fs/ntfs/runlist.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThanOrEqual": "7.2.*",
                "status": "unaffected",
                "version": "7.2.4",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.3-rc1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: verify run length exceeding volume boundary\n\nThe mapping pairs decoder validates that the starting LCN is within the\nvolume but does not check if the run extends beyond the volume boundary.\n\nA malformed NTFS image with a crafted mapping pairs array could cause\nthe kernel to access memory beyond the volume boundary, potentially leading\nto memory corruption and privilege escalation.\n\nAdd validation to ensure lcn + length stays within nr_clusters."
      }
    ],
    "id": "CVE-2026-89610",
    "lastModified": "2026-09-13T07:17:26.507",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-09-11T20:19:46.093",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/6e844d4b82434a781b80d02145fd1b17cf90e3c3"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/fea9e4488f384c0ef1c0e3d96b565127c1b98447"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Received"
  }
}
—
Cvss
cvss
conflict
Red Hat5.5
receipt
Source
Red Hat
Its words
5.5
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-89610",
  "CWE": "CWE-787",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2532418",
  "bugzilla_description": "kernel: ntfs: verify run length exceeding volume boundary",
  "cvss3_score": "5.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-11T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-89610.json",
  "severity": "moderate"
}
—
Cwe
cwe
Red HatCWE-787
receipt
Source
Red Hat
Its words
CWE-787
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-89610",
  "CWE": "CWE-787",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2532418",
  "bugzilla_description": "kernel: ntfs: verify run length exceeding volume boundary",
  "cvss3_score": "5.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-11T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-89610.json",
  "severity": "moderate"
}
—
Product
product
NVDLinux
receipt
Source
NVD
Its words
Linux
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
2026-09-29 17:49 UTCLinux
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "fs/ntfs/runlist.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "6e844d4b82434a781b80d02145fd1b17cf90e3c3",
                "status": "affected",
                "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                "versionType": "git"
              },
              {
                "lessThan": "fea9e4488f384c0ef1c0e3d96b565127c1b98447",
                "status": "affected",
                "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                "versionType": "git"
              },
              {
                "lessThan": "7.2.4",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "fs/ntfs/runlist.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThanOrEqual": "7.2.*",
                "status": "unaffected",
                "version": "7.2.4",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.3-rc1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: verify run length exceeding volume boundary\n\nThe mapping pairs decoder validates that the starting LCN is within the\nvolume but does not check if the run extends beyond the volume boundary.\n\nA malformed NTFS image with a crafted mapping pairs array could cause\nthe kernel to access memory beyond the volume boundary, potentially leading\nto memory corruption and privilege escalation.\n\nAdd validation to ensure lcn + length stays within nr_clusters."
      }
    ],
    "id": "CVE-2026-89610",
    "lastModified": "2026-09-13T07:17:26.507",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-09-11T20:19:46.093",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/6e844d4b82434a781b80d02145fd1b17cf90e3c3"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/fea9e4488f384c0ef1c0e3d96b565127c1b98447"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Received"
  }
}
—
Severity
severity
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-89610",
  "CWE": "CWE-787",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2532418",
  "bugzilla_description": "kernel: ntfs: verify run length exceeding volume boundary",
  "cvss3_score": "5.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-11T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-89610.json",
  "severity": "moderate"
}
medium
Status
status
NVDReceived
receipt
Source
NVD
Its words
Received
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "fs/ntfs/runlist.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "6e844d4b82434a781b80d02145fd1b17cf90e3c3",
                "status": "affected",
                "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                "versionType": "git"
              },
              {
                "lessThan": "fea9e4488f384c0ef1c0e3d96b565127c1b98447",
                "status": "affected",
                "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                "versionType": "git"
              },
              {
                "lessThan": "7.2.4",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "fs/ntfs/runlist.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThanOrEqual": "7.2.*",
                "status": "unaffected",
                "version": "7.2.4",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.3-rc1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: verify run length exceeding volume boundary\n\nThe mapping pairs decoder validates that the starting LCN is within the\nvolume but does not check if the run extends beyond the volume boundary.\n\nA malformed NTFS image with a crafted mapping pairs array could cause\nthe kernel to access memory beyond the volume boundary, potentially leading\nto memory corruption and privilege escalation.\n\nAdd validation to ensure lcn + length stays within nr_clusters."
      }
    ],
    "id": "CVE-2026-89610",
    "lastModified": "2026-09-13T07:17:26.507",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-09-11T20:19:46.093",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/6e844d4b82434a781b80d02145fd1b17cf90e3c3"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/fea9e4488f384c0ef1c0e3d96b565127c1b98447"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Received"
  }
}
—
Vendor
vendor
NVDLinux
receipt
Source
NVD
Its words
Linux
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
2026-09-29 17:49 UTCLinux
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "fs/ntfs/runlist.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "6e844d4b82434a781b80d02145fd1b17cf90e3c3",
                "status": "affected",
                "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                "versionType": "git"
              },
              {
                "lessThan": "fea9e4488f384c0ef1c0e3d96b565127c1b98447",
                "status": "affected",
                "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                "versionType": "git"
              },
              {
                "lessThan": "7.2.4",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "fs/ntfs/runlist.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThanOrEqual": "7.2.*",
                "status": "unaffected",
                "version": "7.2.4",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "7.3-rc1",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: verify run length exceeding volume boundary\n\nThe mapping pairs decoder validates that the starting LCN is within the\nvolume but does not check if the run extends beyond the volume boundary.\n\nA malformed NTFS image with a crafted mapping pairs array could cause\nthe kernel to access memory beyond the volume boundary, potentially leading\nto memory corruption and privilege escalation.\n\nAdd validation to ensure lcn + length stays within nr_clusters."
      }
    ],
    "id": "CVE-2026-89610",
    "lastModified": "2026-09-13T07:17:26.507",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-09-11T20:19:46.093",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/6e844d4b82434a781b80d02145fd1b17cf90e3c3"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/fea9e4488f384c0ef1c0e3d96b565127c1b98447"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Received"
  }
}
—

vulnerability

kernel: ntfs: verify run length exceeding volume boundary
zetlyn/cve-redhat · 2026-09-11
cvss 5.5 cwe CWE-787 severity moderate source
In the Linux kernel, the following vulnerability has been resolved: ntfs: verify run length exceeding volume boundary The mapping pairs decoder validates that the starting LCN is within the volume but does not check if the run extends beyond the volume boundary. A malformed NTFS image with a crafted mapping pairs array could cause the kernel to access memory beyond the volume boundary, potentially leading to memory corruption and privilege escalation. Add validation to ensure lcn + length stays within nr_clusters.
zetlyn/cve-nvd · 2026-09-11
cvss 9.8 product Linux status Received vendor Linux source