Out-of-bounds read in Linux kernel - CVE-2026-89614
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to read out-of-bounds memory.
The vulnerability exists due to an out-of-bounds read in the NTFS cluster allocator when extending a file on an NTFS volume. A local user can extend a file whose last logical cluster number lies outside the volume's cluster range to read out-of-bounds memory.
Exploitation requires a volume whose $Bitmap covers more clusters than the volume.