{"id":"CVE-2026-90048","published":"2026-09-16T11:17:18.140","lastModified":"2026-09-16T15:18:27.570","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list()\n\nni_create_attr_list() allocates a fixed buffer of al_aligned(record_size)\n(== record_size) bytes and then walks every attribute of the primary MFT\nrecord, writing one ATTR_LIST_ENTRY per attribute and advancing the cursor\nby le_size(name_len), with no check against the end of the buffer; the\ntotal size is only computed after the loop.\n\nA minimum-size resident attribute occupies SIZEOF_RESIDENT (0x18 = 24)\nbytes on disk, but an unnamed attribute expands to le_size(0) (0x20 = 32)\nbytes in the list.  Because the number of attributes in a record is not\nbounded (mi_enum_attr() accepts arbitrarily many equal-type, nameless\nminimum-size attributes), a crafted record packed with such attributes\nproduces a list larger than record_size and overflows the heap buffer.\n\nThis is reachable from a crafted, loop-mounted NTFS image: opening the file\nand adding an attribute (e.g. via setxattr) drives ntfs_set_ea() ->\nni_insert_resident() -> ni_insert_attr() -> ni_ins_attr_ext() ->\nni_create_attr_list().\n\n  BUG: KASAN: slab-out-of-bounds in ni_create_attr_list+0xc48/0x1058\n  Write of size 4 at addr ffff000008984c00 by task setfattr/345\n   ni_create_attr_list+0xc48/0x1058\n   ni_ins_attr_ext+0x510/0x7c0\n   ni_insert_attr+0x3f8/0x70c\n   ni_insert_resident+0xc8/0x3b0\n   ntfs_set_ea+0x66c/0xd28\n   ntfs_setxattr+0x4d8/0x5b0\n   __arm64_sys_setxattr+0xa4/0x124\n  Allocated by task 345:\n   ni_create_attr_list+0x188/0x1058\n  The buggy address belongs to the cache kmalloc-1k of size 1024\n  (the write lands at object+1024).\n\nSize the buffer from the actual attributes instead of assuming a single\nrecord_size is always enough.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/7c4841e2a62794a3bab7c1ff0540580f387e377f","tags":[]},{"url":"https://git.kernel.org/stable/c/7e9aee7e4d9767cc3e423b3beecb01c7ebb6bbcd","tags":[]},{"url":"https://git.kernel.org/stable/c/a84f3db72561c4d9281c5ff721ce46b9ffa7f30e","tags":[]},{"url":"https://git.kernel.org/stable/c/d07e281f2a7710502985d6f80b95ddac8f4e81d5","tags":[]},{"url":"https://git.kernel.org/stable/c/fa2215cf451414b0512cd6f7d37a057893811f4d","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a slab-out-of-bounds write in ni_create_attr_list() due to lack of buffer size validation, which can lead to heap buffer overflow when handling crafted NTFS attributes. This matters because it could allow an attacker to execute arbitrary code or cause system instability.","exploitability":"Exploitation requires mounting a specially crafted NTFS image and adding attributes to trigger the vulnerability. It is moderately difficult due to the need for precise attribute crafting but is feasible with proper knowledge.","blast_radius":"If exploited, this could result in remote code execution or denial of service on affected systems, impacting any system using the vulnerable version of the Linux kernel.","remediation":"Update to a patched version of the Linux kernel as soon as possible.","tags":["rce","kernel","ntfs","heap-overflow"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-23T08:45:50.516Z"}}