CVE-2026-64533
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: validate lcns_follow in log_replay conversion
log_replay() converts DIR_PAGE_ENTRY_32 records into DIR_PAGE_ENTRY records when replaying version 0 restart tables.
During this conversion, the memmove() length is derived directly from the on-disk lcns_follow field:
check_rstbl() validates restart table structure, but does not constrain per-entry lcns_follow values relative to the entry size. A malformed filesystem image can provide an oversized lcns_follow value, causing the conversion memmove() to access memory beyond the bounds of the allocated restart table buffer.
Leer descripción completaMostrar menos
The same field is later used to bound iteration over page_lcns[], so validating lcns_follow during conversion also prevents downstream out-of-bounds access from the same malformed metadata.
Compute the maximum valid lcns_follow from the already-validated restart table entry size and reject entries that exceed this bound. Reuse the existing t16/t32 scratch variables already declared in log_replay() to avoid introducing new declarations.
[almaz.alexandrovich@paragon-software.com: fixed the conflicts]
Detalles técnicos trazas, registros y código del informe original
memmove(&dp->vcn, &dp0->vcn_low, 2 * sizeof(u64) + le32_to_cpu(dp->lcns_follow) * sizeof(u64));
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution85 % - Impacto secundario
T1499.004Application or System Exploitationimpact65 %
Requiere interacción del usuario (UI:R) para abrir un filesystem malformado. El memmove sin validación permite ejecución de código o negación de servicio en el kernel.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/159f694d682e4215b3822ae31ed3a4631628fe55
- https://git.kernel.org/stable/c/32b9f8733feb241627fa5f564b1a99b5cae974c5
- https://git.kernel.org/stable/c/57c071e2c4f30b9c6f5aacb6679aab1269fbae99
- https://git.kernel.org/stable/c/6a4c53a2e26a865565bd6a460961e8d6fcb32329
- https://git.kernel.org/stable/c/7adb38279812c9c06b0e3fa7382f4d7887f3fa2d
- https://git.kernel.org/stable/c/ca343a99806b4fc8e27c48f08be3445c5fcd1445
- https://git.kernel.org/stable/c/ddfc8683e1a627dbf1b83bacf8961443dd654258
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-64533",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "b46acd6a6a627d876898e1c84d3f84902264b445",
"lessThan": "ca343a99806b4fc8e27c48f08be3445c5fcd1445",
"versionType": "git"
},
{
"status": "affected",
"version": "b46acd6a6a627d876898e1c84d3f84902264b445",
"lessThan": "ddfc8683e1a627dbf1b83bacf8961443dd654258",
"versionType": "git"
},
{
"status": "affected",
"version": "b46acd6a6a627d876898e1c84d3f84902264b445",
"lessThan": "57c071e2c4f30b9c6f5aacb6679aab1269fbae99",
"versionType": "git"
},
{
"status": "affected",
"version": "b46acd6a6a627d876898e1c84d3f84902264b445",
"lessThan": "159f694d682e4215b3822ae31ed3a4631628fe55",
"versionType": "git"
},
{
"status": "affected",
"version": "b46acd6a6a627d876898e1c84d3f84902264b445",
"lessThan": "7adb38279812c9c06b0e3fa7382f4d7887f3fa2d",
"versionType": "git"
},
{
"status": "affected",
"version": "b46acd6a6a627d876898e1c84d3f84902264b445",
"lessThan": "32b9f8733feb241627fa5f564b1a99b5cae974c5",
"versionType": "git"
},
{
"status": "affected",
"version": "b46acd6a6a627d876898e1c84d3f84902264b445",
"lessThan": "6a4c53a2e26a865565bd6a460961e8d6fcb32329",
"versionType": "git"
}
],
"programFiles": [
"fs/ntfs3/fslog.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/ntfs3/fslog.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-27T08:16:22.510",
"references": [
{
"url": "https://git.kernel.org/stable/c/159f694d682e4215b3822ae31ed3a4631628fe55",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/32b9f8733feb241627fa5f564b1a99b5cae974c5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/57c071e2c4f30b9c6f5aacb6679aab1269fbae99",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6a4c53a2e26a865565bd6a460961e8d6fcb32329",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7adb38279812c9c06b0e3fa7382f4d7887f3fa2d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ca343a99806b4fc8e27c48f08be3445c5fcd1445",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ddfc8683e1a627dbf1b83bacf8961443dd654258",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate lcns_follow in log_replay conversion\n\nlog_replay() converts DIR_PAGE_ENTRY_32 records into DIR_PAGE_ENTRY\nrecords when replaying version 0 restart tables.\n\nDuring this conversion, the memmove() length is derived directly from\nthe on-disk lcns_follow field:\n\n\tmemmove(&dp->vcn, &dp0->vcn_low,\n\t\t2 * sizeof(u64) +\n\t\t\t\tle32_to_cpu(dp->lcns_follow) * sizeof(u64));\n\ncheck_rstbl() validates restart table structure, but does not constrain\nper-entry lcns_follow values relative to the entry size. A malformed\nfilesystem image can provide an oversized lcns_follow value, causing\nthe conversion memmove() to access memory beyond the bounds of the\nallocated restart table buffer.\n\nThe same field is later used to bound iteration over page_lcns[],\nso validating lcns_follow during conversion also prevents downstream\nout-of-bounds access from the same malformed metadata.\n\nCompute the maximum valid lcns_follow from the already-validated\nrestart table entry size and reject entries that exceed this bound.\nReuse the existing t16/t32 scratch variables already declared in\nlog_replay() to avoid introducing new declarations.\n\n[almaz.alexandrovich@paragon-software.com: fixed the conflicts]"
}
],
"lastModified": "2026-08-17T05:17:58.350",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}