SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89616

HIGH · CVSS 7.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the `ni_read_frame()` function within the NTFS3 file system, which can leak uninitialized memory from kernel pages due to improper handling of decompressed data. An attacker can exploit this flaw by crafting a specific compressed file, potentially allowing them to recover sensitive kernel pointers and bypass Kernel Address Space Layout Randomization (KASLR). Linux system administrators and developers working with NTFS3 file systems should prioritize applying the relevant patches to mitigate this risk.

CVE
CVE-2026-89616
Severity
HIGH
CVSS
7.5
EPSS
0.37%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() ni_read_frame() decompresses an LZNT $DATA frame into the vmapped target pages and then trusts decompress_lznt()'s return value: unc_size = decompress_lznt(frame_ondisk, ondisk_size, frame_mem, frame_size); if ((ssize_t)unc_size < 0) err = unc_size; else if (!unc_size || unc_size > frame_size) err = -EINVAL; decompress_lznt() stops as soon as the compressed stream is exhausted (e.g. a zero chunk header) and returns the number of bytes it actually wrote, which may be far less than frame_size. The bytes between unc_size and frame_size are never written. The only memset() that follows zeroes the region beyond i_valid; when the frame lies entirely within the file's valid size that memset() does not run, so the gap retains whatever was in the just-vmapped pages. All pages are then marked uptodate and returned to userspace, disclosing uninitialized (recently-freed) kernel page memory. A crafted compressed file whose stream decompresses to only a few bytes leaks the remainder of every frame on a plain read(2), which is enough to recover kernel pointers and defeat KASLR. Zero the [unc_size, frame_size) tail immediately after a successful LZNT decompress so the remainder reads back as zero.