Heap-based buffer overflow in Linux kernel - CVE-2026-45935
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in DeleteIndexEntryRoot in the ntfs3 filesystem code when processing a crafted log record. A local user can supply a maliciously large entry size value to trigger memory corruption and cause a denial of service.
How to mitigate CVE-2026-45935
Sources
- https://git.kernel.org/stable/c/36c03f7f177b34d51f1cf1d2304b1074607bf4b0
- https://git.kernel.org/stable/c/78942172d5bff4d4afed8674abc09cc560ce44a0
- https://git.kernel.org/stable/c/a584b9d1059b29e97e17c919274e9adfb846f2a0
- https://git.kernel.org/stable/c/b271c9cb85927210b1b799e55ee7f702d12b4336
- https://git.kernel.org/stable/c/b2bc7c44ed1779fc9eaab9a186db0f0d01439622
- https://git.kernel.org/stable/c/c065541b71b79874c83d418a9acd18ad5826339b
- https://git.kernel.org/stable/c/f3b437a4c3e022a1449658ae9f3dd34859894513