{"id":"CVE-2026-89613","title":"kernel: ntfs: reject invalid empty mapping pairs (CVE-2026-89613)","summary":"A flaw was found in the Linux kernel's NTFS filesystem driver. This vulnerability occurs when the driver processes an attribute with empty mapping pairs that have inconsistent highest Virtual Cluster Number (VCN) and size. A local attacker…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-130","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-15","sourceUpdated":"2026-09-15T11:02:18+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89613.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89613.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89613"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532432"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89613"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89613"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89613.mbox"},{"url":"https://git.kernel.org/stable/c/766062a82e1ce4087c7dc077224144dfd34b3661"},{"url":"https://git.kernel.org/stable/c/b0cc6dbc655e037251874b3e0dd1a760dcf29007"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00553,"epssPercentile":0.45059,"scores":{"vendor":4.4,"cna":9.8},"ingestedAt":"2026-09-14T15:23:07.474Z","slug":"CVE-2026-89613","body":"## Overview\n\nA flaw was found in the Linux kernel's NTFS filesystem driver. This vulnerability occurs when the driver processes an attribute with empty mapping pairs that have inconsistent highest Virtual Cluster Number (VCN) and size. A local attacker could potentially craft a malicious NTFS filesystem that, when mounted, could lead to a denial of service by causing the system to become unresponsive or crash.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89613.json)\n\n**kernel: ntfs: reject invalid empty mapping pairs** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":203913,"id":"CVE-2026-89613","ts":1789490220920,"field":"cvss","old":"4.4","new":"5.5"},{"seq":202853,"id":"CVE-2026-89613","ts":1789403732676,"field":"cvss","old":"9.8","new":"4.4"},{"seq":202852,"id":"CVE-2026-89613","ts":1789403732676,"field":"severity","old":"critical","new":"medium"},{"seq":197855,"id":"CVE-2026-89613","ts":1789384320688,"field":"cvss","old":"4.4","new":"9.8"},{"seq":197854,"id":"CVE-2026-89613","ts":1789384320688,"field":"severity","old":"medium","new":"critical"},{"seq":183418,"id":"CVE-2026-89613","ts":1789356675285,"field":"cvss","old":"9.8","new":"4.4"},{"seq":183417,"id":"CVE-2026-89613","ts":1789356675285,"field":"severity","old":"critical","new":"medium"},{"seq":153444,"id":"CVE-2026-89613","ts":1789285350537,"field":"cvss","old":null,"new":"9.8"},{"seq":153443,"id":"CVE-2026-89613","ts":1789285350537,"field":"severity","old":"none","new":"critical"},{"seq":147221,"id":"CVE-2026-89613","ts":1789270202276,"field":"cvss","old":null,"new":"4.4"},{"seq":147220,"id":"CVE-2026-89613","ts":1789270202276,"field":"severity","old":"none","new":"medium"},{"seq":108974,"id":"CVE-2026-89613","ts":1789183729798,"field":"cvss","old":null,"new":"4.4"},{"seq":108973,"id":"CVE-2026-89613","ts":1789183729798,"field":"severity","old":"none","new":"medium"}]}