{"id":"CVE-2026-89779","summary":"fs/ntfs3: validate ef-\u003esize covers the record's name and value","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate ef-\u003esize covers the record's name and value\n\nWhen an EA record has a non-zero ef-\u003esize, ntfs_read_ea() only checks\nthat the record fits in the remaining buffer (ea_size \u003e bytes), not that\nef-\u003esize is large enough to hold the record's own name_len + 1 + elength.\n\nA crafted image can pass validation with, e.g., ef-\u003esize = 24 but\nelength = 0xffff. ntfs_get_ea() then trusts elength and copies it out of\nthe undersized record, reading past the kmalloc(info-\u003esize) allocation\nand leaking heap memory to userspace via getxattr():\n\n BUG: KASAN: slab-out-of-bounds in ntfs_get_ea (fs/ntfs3/xattr.c:302)\n Read of size 65535 at addr ffff888100794550 by task exploit\n  __asan_memcpy (mm/kasan/shadow.c:105)\n  ntfs_get_ea (fs/ntfs3/xattr.c:302)\n  ntfs_getxattr (fs/ntfs3/xattr.c:848)\n  __vfs_getxattr (fs/xattr.c:441)\n  vfs_getxattr (fs/xattr.c:474)\n  do_getxattr (fs/xattr.c:800)\n  path_getxattrat (fs/xattr.c:868)\n  do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n\n The buggy address is located 80 bytes inside of\n  allocated 84-byte region in cache kmalloc-96\n\nCompute the size the record needs and require ef-\u003esize to cover it.","modified":"2026-09-17T03:47:26.834991273Z","published":"2026-09-16T08:48:19.083Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89779.json"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/077df8464cf24f8ffc82fb6efec2ae600686e699"},{"type":"WEB","url":"https://git.kernel.org/stable/c/28a924c7e67e6d71abeb04860b61166fecb027fc"},{"type":"WEB","url":"https://git.kernel.org/stable/c/aab1880058ac767d3ea9388a9a7221c776c22c44"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b27e68ad818a4ca2cef8f35f97e75d756714c818"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c22f91d82cb9a29d22bdffdce6c803467984ad0c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c8a109c9e23a2c7fd548473dde728b2cb8188146"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d585ed08308909c7e6fefb4e8a258aeb29b19ff9"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89779.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89779"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"333feb7ba84f69f9b423422417aaac54fd9e7c84"},{"fixed":"b27e68ad818a4ca2cef8f35f97e75d756714c818"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"000a9a72efa4a9df289bab9c9e8ba1639c72e0d6"},{"fixed":"28a924c7e67e6d71abeb04860b61166fecb027fc"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b"},{"fixed":"d585ed08308909c7e6fefb4e8a258aeb29b19ff9"},{"fixed":"077df8464cf24f8ffc82fb6efec2ae600686e699"},{"fixed":"aab1880058ac767d3ea9388a9a7221c776c22c44"},{"fixed":"c8a109c9e23a2c7fd548473dde728b2cb8188146"},{"fixed":"c22f91d82cb9a29d22bdffdce6c803467984ad0c"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5.15.121"},{"fixed":"5.15.221"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6.1.40"},{"fixed":"6.1.188"}]}],"versions":["v5.15.220","v5.15.219","v5.15.218","v5.15.217","v5.15.216","v5.15.215","v5.15.214","v5.15.213","v5.15.212","v5.15.211","v5.15.210","v5.15.209","v5.15.208","v5.15.207","v5.15.206","v5.15.205","v5.15.204","v5.15.203","v5.15.202","v5.15.201","v5.15.200","v5.15.199","v5.15.198","v5.15.197","v5.15.196","v5.15.195","v5.15.194","v5.15.193","v5.15.192","v5.15.191","v5.15.190","v5.15.189","v5.15.188","v5.15.187","v5.15.186","v5.15.185","v5.15.184","v5.15.183","v5.15.182","v5.15.181","v5.15.180","v5.15.179","v5.15.178","v5.15.177","v5.15.176","v5.15.175","v5.15.174","v5.15.173","v5.15.172","v5.15.171","v5.15.170","v5.15.169","v5.15.168","v5.15.167","v5.15.166","v5.15.165","v5.15.164","v5.15.163","v5.15.162","v5.15.161","v5.15.160","v5.15.159","v5.15.158","v5.15.157","v5.15.156","v5.15.155","v5.15.154","v5.15.153","v5.15.152","v5.15.151","v5.15.150","v5.15.149","v5.15.148","v5.15.147","v5.15.146","v5.15.145","v5.15.144","v5.15.143","v5.15.142","v5.15.141","v5.15.140","v5.15.139","v5.15.138","v5.15.137","v5.15.136","v5.15.135","v5.15.134","v5.15.133","v5.15.132","v5.15.131","v5.15.130","v5.15.129","v5.15.128","v5.15.127","v5.15.126","v5.15.125","v5.15.124","v5.15.123","v5.15.122","v5.15.121","v6.1.187","v6.1.186","v6.1.185","v6.1.184","v6.1.183","v6.1.182","v6.1.181","v6.1.180","v6.1.179","v6.1.178","v6.1.177","v6.1.176","v6.1.175","v6.1.174","v6.1.173","v6.1.172","v6.1.171","v6.1.170","v6.1.169","v6.1.168","v6.1.167","v6.1.166","v6.1.165","v6.1.164","v6.1.163","v6.1.162","v6.1.161","v6.1.160","v6.1.159","v6.1.158","v6.1.157","v6.1.156","v6.1.155","v6.1.154","v6.1.153","v6.1.152","v6.1.151","v6.1.150","v6.1.149","v6.1.148","v6.1.147","v6.1.146","v6.1.145","v6.1.144","v6.1.143","v6.1.142","v6.1.141","v6.1.140","v6.1.139","v6.1.138","v6.1.137","v6.1.136","v6.1.135","v6.1.134","v6.1.133","v6.1.132","v6.1.131","v6.1.130","v6.1.129","v6.1.128","v6.1.127","v6.1.126","v6.1.125","v6.1.124","v6.1.123","v6.1.122","v6.1.121","v6.1.120","v6.1.119","v6.1.118","v6.1.117","v6.1.116","v6.1.115","v6.1.114","v6.1.113","v6.1.112","v6.1.111","v6.1.110","v6.1.109","v6.1.108","v6.1.107","v6.1.106","v6.1.105","v6.1.104","v6.1.103","v6.1.102","v6.1.101","v6.1.100","v6.1.99","v6.1.98","v6.1.97","v6.1.96","v6.1.95","v6.1.94","v6.1.93","v6.1.92","v6.1.91","v6.1.90","v6.1.89","v6.1.88","v6.1.87","v6.1.86","v6.1.85","v6.1.84","v6.1.83","v6.1.82","v6.1.81","v6.1.80","v6.1.79","v6.1.78","v6.1.77","v6.1.76","v6.1.75","v6.1.74","v6.1.73","v6.1.72","v6.1.71","v6.1.70","v6.1.69","v6.1.68","v6.1.67","v6.1.66","v6.1.65","v6.1.64","v6.1.63","v6.1.62","v6.1.61","v6.1.60","v6.1.59","v6.1.58","v6.1.57","v6.1.56","v6.1.55","v6.1.54","v6.1.53","v6.1.52","v6.1.51","v6.1.50","v6.1.49","v6.1.48","v6.1.47","v6.1.46","v6.1.45","v6.1.44","v6.1.43","v6.1.42","v6.1.41","v6.1.40"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89779.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.221"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.188"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.157"},{"fixed":"6.12.110"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.18.52"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"7.2.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89779.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}