Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-98133
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause existing extended attributes to be hidden.
The vulnerability exists due to incorrect state handling in ntfs_set_ea() when handling a failed extended attribute update. A local user can trigger a failure while setting an extended attribute to cause existing extended attributes to be hidden.
The attributes remain hidden until the inode is evicted.