Out-of-bounds write in Linux kernel - CVE-2026-90048
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to an out-of-bounds write in ni_create_attr_list() in the NTFS3 filesystem driver when processing a crafted loop-mounted NTFS image. A remote attacker can craft an NTFS image containing many nameless minimum-size resident attributes to compromise confidentiality, integrity, and availability.
Exploitation is reached by opening a file on the mounted image and adding an attribute.
Affected software
How to mitigate CVE-2026-90048
External References
- https://git.kernel.org/stable/c/7c4841e2a62794a3bab7c1ff0540580f387e377f
- https://git.kernel.org/stable/c/7e9aee7e4d9767cc3e423b3beecb01c7ebb6bbcd
- https://git.kernel.org/stable/c/a84f3db72561c4d9281c5ff721ce46b9ffa7f30e
- https://git.kernel.org/stable/c/d07e281f2a7710502985d6f80b95ddac8f4e81d5
- https://git.kernel.org/stable/c/fa2215cf451414b0512cd6f7d37a057893811f4d