CVE-2026-98315 (GCVE-0-2026-98315)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:46 – Updated: 2026-10-07 06:49
VLAI
Title
ntfs: protect runlist updates with the runlist lock
Summary
In the Linux kernel, the following vulnerability has been resolved: ntfs: protect runlist updates with the runlist lock ntfs_non_resident_attr_shrink() calls runlist helpers that require the runlist write lock, but did not hold it while freeing clusters and truncating the runlist. Serialize those operations and the resident conversion with the runlist lock. ntfs_attr_map_cluster() can merge a newly allocated run before updating mapping pairs. If the update fails, free the clusters and restore both the in-memory runlist and on-disk mapping pairs from a saved runlist. Mark the volume in error if either rollback step fails.
Impacted products
Vendor Product Version
Linux Linux Affected: 495e90fa334828d4119061e2726af51d0a0fb4ed , < 742797432e8c9b0dd54ecc523c185e26b09d79a0 (git)
Affected: 495e90fa334828d4119061e2726af51d0a0fb4ed , < 91709ba5d6d709b2b663287b7e871e2c6b480502 (git)
Create a notification for this product.
Linux Linux Affected: 7.1
Unaffected: 0 , < 7.1 (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/ntfs/attrib.c",
            "fs/ntfs/attrib.h",
            "fs/ntfs/attrlist.c",
            "fs/ntfs/attrlist.h",
            "fs/ntfs/compress.c",
            "fs/ntfs/file.c",
            "fs/ntfs/inode.c",
            "fs/ntfs/mft.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "742797432e8c9b0dd54ecc523c185e26b09d79a0",
              "status": "affected",
              "version": "495e90fa334828d4119061e2726af51d0a0fb4ed",
              "versionType": "git"
            },
            {
              "lessThan": "91709ba5d6d709b2b663287b7e871e2c6b480502",
              "status": "affected",
              "version": "495e90fa334828d4119061e2726af51d0a0fb4ed",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/ntfs/attrib.c",
            "fs/ntfs/attrib.h",
            "fs/ntfs/attrlist.c",
            "fs/ntfs/attrlist.h",
            "fs/ntfs/compress.c",
            "fs/ntfs/file.c",
            "fs/ntfs/inode.c",
            "fs/ntfs/mft.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "lessThan": "7.1",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "7.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "7.1",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: protect runlist updates with the runlist lock\n\nntfs_non_resident_attr_shrink() calls runlist helpers that require the\nrunlist write lock, but did not hold it while freeing clusters and\ntruncating the runlist. Serialize those operations and the resident\nconversion with the runlist lock.\n\nntfs_attr_map_cluster() can merge a newly allocated run before updating\nmapping pairs. If the update fails, free the clusters and restore both\nthe in-memory runlist and on-disk mapping pairs from a saved runlist.\nMark the volume in error if either rollback step fails."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The trigger is a local ftruncate() on a file in a mounted NTFS volume, via ntfs_setattr_size()-\u003entfs_truncate_vfs()-\u003e__ntfs_attr_truncate_vfs()-\u003entfs_non_resident_attr_shrink(). That path frees clusters and calls ntfs_rl_truncate_nolock() without ni-\u003erunlist.lock. No remote protocol supplies the input; it is a locking defect on a well-formed volume.\nAC:L - The attacker runs both sides of the race: one thread dirties and fsync()s the file, driving ntfs_writeback_range()-\u003e__ntfs_write_iomap_begin(), which walks and merges ni-\u003erunlist.rl under runlist.lock. Another thread repeatedly ftruncate()s the same file, reallocating or kvfree()ing rl without that lock. It can be retried at will.\nPR:L - The attacker only needs an ordinary local account with write permission on a file in an already-mounted NTFS volume, as needed for setattr ATTR_SIZE and writeback. No capability is checked on this path.\nUI:N - No crafted image or victim mount is needed. The race works against any legitimately mounted NTFS volume, using only the attacker\u0027s own truncate and write/fsync calls on a file the attacker can already write.\nS:U - The memory corruption stays within the kernel\u0027s own security authority. No guest/host, IOMMU or sandbox boundary is crossed.\nC:H - ntfs_rl_truncate_nolock() reallocates or frees the kvmalloc\u0027d runlist array while writeback still holds a pointer into it, so the freed slab can be reclaimed and its contents read back as cluster mappings (LCNs). That can direct I/O at arbitrary disk clusters, and is a use-after-free read of kernel memory.\nI:H - The writeback path merges new runs into the freed or reallocated runlist array (heap use-after-free write). Concurrently, ntfs_cluster_free() and the shrink update the shared runlist and on-disk mapping pairs without serialization, corrupting both kernel heap memory and filesystem metadata.\nA:H - Losing the race leads to a KASAN use-after-free or oops in the runlist walk, a double kvfree, or a corrupted runlist and mapping pairs that leave the volume inconsistent and can crash later lookups."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-07T06:49:59.515Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/742797432e8c9b0dd54ecc523c185e26b09d79a0"
        },
        {
          "url": "https://git.kernel.org/stable/c/91709ba5d6d709b2b663287b7e871e2c6b480502"
        }
      ],
      "title": "ntfs: protect runlist updates with the runlist lock",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98315",
    "datePublished": "2026-10-06T08:46:10.751Z",
    "dateReserved": "2026-09-25T10:25:14.339Z",
    "dateUpdated": "2026-10-07T06:49:59.515Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98315",
      "date": "2026-10-09",
      "epss": "0.00129",
      "percentile": "0.02214"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "fs/ntfs/attrib.c",
                  "fs/ntfs/attrib.h",
                  "fs/ntfs/attrlist.c",
                  "fs/ntfs/attrlist.h",
                  "fs/ntfs/compress.c",
                  "fs/ntfs/file.c",
                  "fs/ntfs/inode.c",
                  "fs/ntfs/mft.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "742797432e8c9b0dd54ecc523c185e26b09d79a0",
                    "status": "affected",
                    "version": "495e90fa334828d4119061e2726af51d0a0fb4ed",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "91709ba5d6d709b2b663287b7e871e2c6b480502",
                    "status": "affected",
                    "version": "495e90fa334828d4119061e2726af51d0a0fb4ed",
                    "versionType": "git"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "fs/ntfs/attrib.c",
                  "fs/ntfs/attrib.h",
                  "fs/ntfs/attrlist.c",
                  "fs/ntfs/attrlist.h",
                  "fs/ntfs/compress.c",
                  "fs/ntfs/file.c",
                  "fs/ntfs/inode.c",
                  "fs/ntfs/mft.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "lessThan": "7.1",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: protect runlist updates with the runlist lock\n\nntfs_non_resident_attr_shrink() calls runlist helpers that require the\nrunlist write lock, but did not hold it while freeing clusters and\ntruncating the runlist. Serialize those operations and the resident\nconversion with the runlist lock.\n\nntfs_attr_map_cluster() can merge a newly allocated run before updating\nmapping pairs. If the update fails, free the clusters and restore both\nthe in-memory runlist and on-disk mapping pairs from a saved runlist.\nMark the volume in error if either rollback step fails."
          }
        ],
        "id": "CVE-2026-98315",
        "lastModified": "2026-10-07T07:17:08.617",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 1.8,
              "impactScore": 5.9,
              "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
              "type": "Secondary"
            }
          ]
        },
        "published": "2026-10-06T09:18:23.200",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/742797432e8c9b0dd54ecc523c185e26b09d79a0"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/91709ba5d6d709b2b663287b7e871e2c6b480502"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "suse_vex": {
      "aggregate_severity": "moderate",
      "current_release_date": "2026-10-08T16:47:49Z",
      "cve": "CVE-2026-98315",
      "id": "CVE-2026-98315",
      "initial_release_date": "2026-10-08T16:47:49Z",
      "product_status:known_not_affected": "347",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98315",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98315.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…