SB2026052806 - Integer overflow in Linux kernel ntfs3
Published: May 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer overflow (CVE-ID: CVE-2026-46062)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to integer overflow in run_unpack() when processing crafted ntfs metadata. A local user can provide a specially crafted ntfs image to trigger the overflow and cause a denial of service.
The issue was found by fuzzing.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/60dab3e2931f3d792438a77a6cb0cb731c43300b
- https://git.kernel.org/stable/c/6175d09c23bec4b60860ee9a0170308ff4b56e10
- https://git.kernel.org/stable/c/984a415f019536ea2d24de9010744e5302a9a948
- https://git.kernel.org/stable/c/a954061b334ec67c79ae9d0cadd83fa521396487
- https://git.kernel.org/stable/c/f1af27cec07a9fd0847166bdb23c99e86b05bfdc