Incorrect Conversion between Numeric Types in Linux kernel - CVE-2026-89612
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds access.
The vulnerability exists due to improper numeric type conversion in parse_ntfs_boot_sector() in the NTFS filesystem driver when parsing a crafted NTFS boot sector. A local user can provide high-bit MFT or MFTMirr LCN values that are interpreted as negative values to cause an out-of-bounds access.