« Volver al listado

CVE-2026-90117

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ntfs: validate usa_ofs before preserving the update sequence number

When ntfs_mft_record_alloc() reuses a free mft record it reads the old update sequence number straight from the on-disk record:

Here m points into the raw $MFT page-cache folio, which still holds unvalidated, MST-protected bytes: the folio is read by a plain iomap_read_folio() and neither post_read_mst_fixup() nor ntfs_mft_record_check() has run on it (both work on private copies). m->usa_ofs is therefore an untrusted u16, and a corrupted record can put it past the end of the record so the two-byte read lands outside the folio. Reading such a record while creating a file gives, under KASAN:

Leer descripción completaMostrar menos

Only preserve the old update sequence number when usa_ofs is even and in range, mirroring the check ntfs_mft_record_check() already applies; otherwise leave usn zero, which the existing restore below skips.

Detalles técnicos trazas, registros y código del informe original
     usn = *(__le16 *)((u8 *)m + le16_to_cpu(m->usa_ofs));

   BUG: KASAN: use-after-free in ntfs_mft_record_alloc+...
   Read of size 2 at addr ...
    ntfs_mft_record_alloc -> __ntfs_create -> ntfs_create -> path_openat

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90117",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "495e90fa334828d4119061e2726af51d0a0fb4ed",
              "lessThan": "ea5a3c30710710c1dc5e483d3313309ec2e868f7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "495e90fa334828d4119061e2726af51d0a0fb4ed",
              "lessThan": "81684340963da2e898eabb8c1e274433d9375bc6",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/ntfs/mft.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/ntfs/mft.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:03.857",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/81684340963da2e898eabb8c1e274433d9375bc6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ea5a3c30710710c1dc5e483d3313309ec2e868f7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: validate usa_ofs before preserving the update sequence number\n\nWhen ntfs_mft_record_alloc() reuses a free mft record it reads the old\nupdate sequence number straight from the on-disk record:\n\n     usn = *(__le16 *)((u8 *)m + le16_to_cpu(m->usa_ofs));\n\nHere m points into the raw $MFT page-cache folio, which still holds\nunvalidated, MST-protected bytes: the folio is read by a plain\niomap_read_folio() and neither post_read_mst_fixup() nor\nntfs_mft_record_check() has run on it (both work on private copies).\nm->usa_ofs is therefore an untrusted u16, and a corrupted record can put\nit past the end of the record so the two-byte read lands outside the\nfolio.  Reading such a record while creating a file gives, under KASAN:\n\n   BUG: KASAN: use-after-free in ntfs_mft_record_alloc+...\n   Read of size 2 at addr ...\n    ntfs_mft_record_alloc -> __ntfs_create -> ntfs_create -> path_openat\n\nOnly preserve the old update sequence number when usa_ofs is even and in\nrange, mirroring the check ntfs_mft_record_check() already applies;\notherwise leave usn zero, which the existing restore below skips."
    }
  ],
  "lastModified": "2026-09-17T17:17:03.857",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}