Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64432

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
27/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns<br /> <br /> In the analysis pass of $LogFile journal replay, log_replay() copies<br /> LCNs from each action log record into an existing Dirty Page Table<br /> (DPT) entry without bounding the destination index. A crafted NTFS<br /> image with DPT entry lcns_follow=1 and an action log record with<br /> lcns_follow=2 produces a kernel slab out-of-bounds write at mount<br /> time:<br /> <br /> BUG: KASAN: slab-out-of-bounds in log_replay+0x654c/0xdb60<br /> Write of size 8 at addr ffff8880095e1040 by task mount<br /> <br /> Two attacker-controlled fields can drive j+i past the allocated<br /> page_lcns[] array:<br /> <br /> 1. dp-&gt;lcns_follow (capacity) can be smaller than lrh-&gt;lcns_follow.<br /> 2. lrh-&gt;target_vcn may be smaller than dp-&gt;vcn, making the u64<br /> subtraction wrap to a huge size_t.<br /> <br /> Validate target VCN delta and per-record LCN count against the<br /> DPT entry capacity, bail via the existing out: cleanup label with<br /> -EINVAL.<br /> <br /> This mirrors the bounds-check pattern added in commit b2bc7c44ed17<br /> ("fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot")<br /> and commit 0ca0485e4b2e ("fs/ntfs3: validate rec-&gt;used in<br /> journal-replay file record check").