CVE-2026-64533
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/07/2026
Last modified:
27/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
fs/ntfs3: validate lcns_follow in log_replay conversion<br />
<br />
log_replay() converts DIR_PAGE_ENTRY_32 records into DIR_PAGE_ENTRY<br />
records when replaying version 0 restart tables.<br />
<br />
During this conversion, the memmove() length is derived directly from<br />
the on-disk lcns_follow field:<br />
<br />
memmove(&dp->vcn, &dp0->vcn_low,<br />
2 * sizeof(u64) +<br />
le32_to_cpu(dp->lcns_follow) * sizeof(u64));<br />
<br />
check_rstbl() validates restart table structure, but does not constrain<br />
per-entry lcns_follow values relative to the entry size. A malformed<br />
filesystem image can provide an oversized lcns_follow value, causing<br />
the conversion memmove() to access memory beyond the bounds of the<br />
allocated restart table buffer.<br />
<br />
The same field is later used to bound iteration over page_lcns[],<br />
so validating lcns_follow during conversion also prevents downstream<br />
out-of-bounds access from the same malformed metadata.<br />
<br />
Compute the maximum valid lcns_follow from the already-validated<br />
restart table entry size and reject entries that exceed this bound.<br />
Reuse the existing t16/t32 scratch variables already declared in<br />
log_replay() to avoid introducing new declarations.<br />
<br />
[almaz.alexandrovich@paragon-software.com: fixed the conflicts]
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/159f694d682e4215b3822ae31ed3a4631628fe55
- https://git.kernel.org/stable/c/32b9f8733feb241627fa5f564b1a99b5cae974c5
- https://git.kernel.org/stable/c/57c071e2c4f30b9c6f5aacb6679aab1269fbae99
- https://git.kernel.org/stable/c/6a4c53a2e26a865565bd6a460961e8d6fcb32329
- https://git.kernel.org/stable/c/7adb38279812c9c06b0e3fa7382f4d7887f3fa2d
- https://git.kernel.org/stable/c/ca343a99806b4fc8e27c48f08be3445c5fcd1445
- https://git.kernel.org/stable/c/ddfc8683e1a627dbf1b83bacf8961443dd654258



