Out-of-bounds read in Linux kernel - CVE-2026-80674
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in NTFS attribute list handling when parsing a crafted resident or truncated $ATTRIBUTE_LIST. A local user can supply a crafted NTFS filesystem image to disclose sensitive information.
User interaction is required to mount or otherwise access the crafted NTFS filesystem.