Out-of-bounds write in Linux kernel - CVE-2026-89615
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to perform an out-of-bounds write.
The vulnerability exists due to an out-of-bounds write in the page_lcns[] array handling of the NTFS3 log replay code when processing a crafted log record. A local user can provide a crafted log record with an lcns_follow count that exceeds the target entry's capacity to perform an out-of-bounds write.