Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-53023

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/06/2026
Última modificación:
15/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> fs/ntfs3: terminate the cached volume label after UTF-8 conversion<br /> <br /> ntfs_fill_super() loads the on-disk volume label with utf16s_to_utf8s()<br /> and stores the result in sbi-&gt;volume.label. The converted label is later<br /> exposed through ntfs3_label_show() using %s, but utf16s_to_utf8s() only<br /> returns the number of bytes written and does not add a trailing NUL.<br /> <br /> If the converted label fills the entire fixed buffer,<br /> ntfs3_label_show() can read past the end of sbi-&gt;volume.label while<br /> looking for a terminator.<br /> <br /> Terminate the cached label explicitly after a successful conversion and<br /> clamp the exact-full case to the last byte of the buffer.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.15 (incluyendo) 5.15.209 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (incluyendo) 6.1.175 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (incluyendo) 6.6.141 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.91 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.33 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.10 (excluyendo)