Missing Authorization in Linux kernel - CVE-2026-90132
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to modify reserved $LX* extended attributes.
The vulnerability exists due to improper access control in ntfs_setxattr when setting reserved $LX* extended attributes from userspace. A local user can set a reserved extended attribute to modify reserved $LX* extended attributes.
The reserved attribute names are $LXUID, $LXGID, $LXMOD, and $LXDEV.