{"id":"CVE-2026-98135","published":"2026-09-25T11:17:44.933","lastModified":"2026-09-25T11:17:44.933","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: reject invalid sectors_per_cluster in the boot sector\n\nis_boot_sector_ntfs() checks the boot sector's sectors_per_cluster field\nwith a range test that rejects 0x81..0xf3 but accepts 0 and other\nnon-power-of-two counts. A zero value reaches parse_ntfs_boot_sector():\n\n\tsectors_per_cluster_bits = ffs(sectors_per_cluster) - 1;\n\t...\n\tvol->cluster_size = vol->sector_size << sectors_per_cluster_bits;\n\nffs(0) is 0, so sectors_per_cluster_bits becomes (unsigned)-1 and the\nshift is undefined:\n\n  UBSAN: shift-out-of-bounds in fs/ntfs/super.c:673:39\n  shift exponent 4294967295 is too large for 32-bit type 'int'\n\nThis change rejects any non-power-of-two value, since it feeds the\naforementioned shift via ffs() - 1, which only yields the correct shift for a\npower of two.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/323751a604e7533fa473874d999371592a614207","tags":[]},{"url":"https://git.kernel.org/stable/c/7524c3145a3bac92bebbc47a29c007f1d874c9b3","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}