Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-89610
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper validation of run length in the NTFS mapping pairs decoder when processing a malformed NTFS image containing a crafted mapping pairs array. A remote attacker can provide a malformed NTFS image with a crafted mapping pairs array to escalate privileges.