Improper input validation in Linux kernel - CVE-2026-89613
Published: September 13, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to failure to reject invalid empty mapping pairs in the NTFS mapping-pairs decompression routine when processing an NTFS attribute with empty mapping pairs and inconsistent metadata. A local user can pass a crafted NTFS attribute to write arbitrary data and eventually execute code with elevated privileges.