Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-98133

 

Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-98133

Published: September 28, 2026


Vulnerability identifier: #VU152317
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-98133
CWE-ID: CWE-670
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause existing extended attributes to be hidden.

The vulnerability exists due to incorrect state handling in ntfs_set_ea() when handling a failed extended attribute update. A local user can trigger a failure while setting an extended attribute to cause existing extended attributes to be hidden.

The attributes remain hidden until the inode is evicted.


Affected software

Linux kernel

How to mitigate CVE-2026-98133

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins