Heap-based buffer overflow in Linux kernel - CVE-2026-90133
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in ntfs_ir_to_ib() when processing a crafted filesystem image. A local user can provide a crafted filesystem image with index root entries exceeding the available index block space to cause a denial of service.