Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-98135
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to trigger undefined behavior in the kernel.
The vulnerability exists due to improper validation of a specified quantity in NTFS boot sector validation when parsing a crafted NTFS boot sector. A local user can provide an NTFS boot sector with an invalid sectors_per_cluster value to trigger undefined behavior in the kernel.