NULL pointer dereference in Linux kernel - CVE-2026-97439
Published: September 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the ntfs3 extended attribute handler when modifying system.ntfs_attrib and system.dos_attrib on the same file in a corrupted ntfs3 image. A local user can toggle system.ntfs_attrib, overwrite system.dos_attrib, and write to the file to cause a denial of service.