Integer overflow in Linux kernel - CVE-2026-80672
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an integer truncation leading to an out-of-bounds read in ntfs_check_restart_area() and ntfs_check_log_client_array() when mounting a crafted NTFS image. A local user can provide a specially crafted NTFS image to disclose sensitive information.
The issue is reachable during mount time while processing the $LogFile restart area and its log client record array.