CVE-2026-64432 Details
Description
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns In the analysis pass of $LogFile journal replay, log_replay() copies LCNs from each action log record into an existing Dirty Page Table (DPT) entry without bounding the destination index. A crafted NTFS image with DPT entry lcns_follow=1 and an action log record with lcns_follow=2 produces a kernel slab out-of-bounds write at mount time: BUG: KASAN: slab-out-of-bounds in log_replay+0x654c/0xdb60 Write of size 8 at addr ffff8880095e1040 by task mount Two attacker-controlled fields can drive j+i past the allocated page_lcns[] array: 1. dp->lcns_follow (capacity) can be smaller than lrh->lcns_follow. 2. lrh->target_vcn may be smaller than dp->vcn, making the u64 subtraction wrap to a huge size_t. Validate target VCN delta and per-record LCN count against the DPT entry capacity, bail via the existing out: cleanup label with -EINVAL. This mirrors the bounds-check pattern added in commit b2bc7c44ed17 ("fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot") and commit 0ca0485e4b2e ("fs/ntfs3: validate rec->used in journal-replay file record check").
A vulnerability in the Linux kernel's NTFS3 file system implementation can lead to a slab out-of-bounds write. This issue occurs during the analysis pass of the $LogFile journal replay, where the log_replay() function copies Logical Cluster Numbers (LCNs) from action log records into an existing Dirty Page Table (DPT) entry. The vulnerability arises because the destination index is not properly bounded. An attacker can exploit this by crafting an NTFS image with a specific DPT entry and action log record, causing the kernel to write beyond the allocated memory. The vulnerability has been addressed by adding proper validation to ensure that the LCN counts and target VCNs do not exceed the DPT entry capacity.
Users should upgrade to the latest version of the Linux kernel where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/3aa96956ca2200674e2a8f9c23ec6ecd45e5010f | kernel.org | Patch |
| https://git.kernel.org/stable/c/57382ec6ac63b63dce2789e835fded28b698ae79 | kernel.org | Patch |
| https://git.kernel.org/stable/c/946046841013ebac8492ef49651c53638d7a9a6a | kernel.org | Patch |
| https://git.kernel.org/stable/c/964c3fae1dfc49dde5468eace940f199cda234e9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c6f9e804f73ef809529865fbc7256dd189ff8c33 | kernel.org | Patch |
| https://git.kernel.org/stable/c/cf28fc1658463d768657cf1c27a83980d4ba7ef2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f433acc85b86f327d03ba8b03a33c105c51053de | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.15, < 5.15.212 >= 5.16, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 27, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |