« Volver al listado

CVE-2026-97439

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib

[BUG] A corrupted ntfs3 image can hit a NULL function pointer call in generic_perform_write() after toggling system.ntfs_attrib and then overwriting system.dos_attrib on the same file.

[CAUSE] system.ntfs_attrib updates ATTR_DATA flags via ni_new_attr_flags() and switches i_mapping->a_ops to ntfs_aops_cmpr when FILE_ATTRIBUTE_COMPRESSED is set. system.dos_attrib then overwrites ni->std_fa from a one-byte DOS attribute value, clearing the compression bit without updating ATTR_DATA or the mapping operations.

Leer descripción completaMostrar menos

Old buffered writes use is_compressed(ni) to choose __generic_file_write_iter(). That leaves generic_perform_write() calling a NULL write_begin callback from ntfs_aops_cmpr.

[FIX] Treat system.dos_attrib as a low-byte DOS attribute update and preserve the existing non-DOS attribute bits in ni->std_fa. This keeps compressed and sparse state consistent with ATTR_DATA and the mapping operations while keeping the existing DOS attribute semantics intact.

Detalles técnicos trazas, registros y código del informe original
BUG: kernel NULL pointer dereference, address: 0000000000000000
\#PF: supervisor instruction fetch in kernel mode
\#PF: error_code(0x0010) - not-present page
PGD bed5067 P4D bed5067 PUD 0
Oops: Oops: 0010 [#1] SMP KASAN NOPTI
RIP: 0010:0x0
Code: Unable to access opcode bytes at 0xffffffffffffffd6.
RSP: 0018:ffff88801025f988 EFLAGS: 00010246
Call Trace:
 generic_perform_write+0x409/0x8c0 mm/filemap.c:4255
 __generic_file_write_iter+0x1bb/0x200 mm/filemap.c:4372
 ntfs_file_write_iter+0xcd9/0x1c20 fs/ntfs3/file.c:1253
 new_sync_write fs/read_write.c:593 [inline]
 vfs_write+0x63b/0xf70 fs/read_write.c:686
 ksys_write+0x133/0x250 fs/read_write.c:738
 __do_sys_write fs/read_write.c:749 [inline]
 __se_sys_write fs/read_write.c:746 [inline]
 __x64_sys_write+0x77/0xc0 fs/read_write.c:746
 ...

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97439",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "be71b5cba2e6485e8959da7a9f9a44461a1bb074",
              "lessThan": "533217b90addd57cc16f1c974e023c72d18949c7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "be71b5cba2e6485e8959da7a9f9a44461a1bb074",
              "lessThan": "f2d6bc89e2236939df189831707c8cdad199f57a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "be71b5cba2e6485e8959da7a9f9a44461a1bb074",
              "lessThan": "fdc9f65aa6631df04238c6154713bacd5133d77c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "be71b5cba2e6485e8959da7a9f9a44461a1bb074",
              "lessThan": "2de91ae285b0b878604d2bd83c3c395a8071e482",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "be71b5cba2e6485e8959da7a9f9a44461a1bb074",
              "lessThan": "407ee19828a7d9700969ed9cc53be50d0f533619",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "be71b5cba2e6485e8959da7a9f9a44461a1bb074",
              "lessThan": "b1c1101067d9536bcb0fe023b96ee2dde5535959",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/ntfs3/xattr.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/ntfs3/xattr.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:22.073",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2de91ae285b0b878604d2bd83c3c395a8071e482",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/407ee19828a7d9700969ed9cc53be50d0f533619",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/533217b90addd57cc16f1c974e023c72d18949c7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b1c1101067d9536bcb0fe023b96ee2dde5535959",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f2d6bc89e2236939df189831707c8cdad199f57a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fdc9f65aa6631df04238c6154713bacd5133d77c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib\n\n[BUG]\nA corrupted ntfs3 image can hit a NULL function pointer call in\ngeneric_perform_write() after toggling system.ntfs_attrib and then\noverwriting system.dos_attrib on the same file.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\n\\#PF: supervisor instruction fetch in kernel mode\n\\#PF: error_code(0x0010) - not-present page\nPGD bed5067 P4D bed5067 PUD 0\nOops: Oops: 0010 [#1] SMP KASAN NOPTI\nRIP: 0010:0x0\nCode: Unable to access opcode bytes at 0xffffffffffffffd6.\nRSP: 0018:ffff88801025f988 EFLAGS: 00010246\nCall Trace:\n generic_perform_write+0x409/0x8c0 mm/filemap.c:4255\n __generic_file_write_iter+0x1bb/0x200 mm/filemap.c:4372\n ntfs_file_write_iter+0xcd9/0x1c20 fs/ntfs3/file.c:1253\n new_sync_write fs/read_write.c:593 [inline]\n vfs_write+0x63b/0xf70 fs/read_write.c:686\n ksys_write+0x133/0x250 fs/read_write.c:738\n __do_sys_write fs/read_write.c:749 [inline]\n __se_sys_write fs/read_write.c:746 [inline]\n __x64_sys_write+0x77/0xc0 fs/read_write.c:746\n ...\n\n[CAUSE]\nsystem.ntfs_attrib updates ATTR_DATA flags via ni_new_attr_flags()\nand switches i_mapping->a_ops to ntfs_aops_cmpr when\nFILE_ATTRIBUTE_COMPRESSED is set. system.dos_attrib then overwrites\nni->std_fa from a one-byte DOS attribute value, clearing the compression\nbit without updating ATTR_DATA or the mapping operations.\n\nOld buffered writes use is_compressed(ni) to choose\n__generic_file_write_iter(). That leaves generic_perform_write() calling\na NULL write_begin callback from ntfs_aops_cmpr.\n\n[FIX]\nTreat system.dos_attrib as a low-byte DOS attribute update and preserve the\nexisting non-DOS attribute bits in ni->std_fa. This keeps compressed and\nsparse state consistent with ATTR_DATA and the mapping operations while\nkeeping the existing DOS attribute semantics intact."
    }
  ],
  "lastModified": "2026-10-03T11:17:55.520",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}