{"id":"CVE-2026-89617","title":"kernel: fs/ntfs3: validate dirty page table on log replay (CVE-2026-89617)","summary":"A flaw was found in the Linux kernel's NTFS3 filesystem driver. An attacker with local access could craft a malicious NTFS log file. During log replay, insufficient validation of the `lcns_follow` field in a `DIR_PAGE_ENTRY` could lead to …","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-787","vendor":"Red Hat","product":"Linux","affected":["Linux >= b46acd6a6a627d876898e1c84d3f84902264b445 < 0e07ea2fc45a7b4757ef7bf1f692cc0180a08323","Linux >= b46acd6a6a627d876898e1c84d3f84902264b445 < 1e90b1703ee1a04cd3e9e399353fc536f5f3ba10","Linux >= b46acd6a6a627d876898e1c84d3f84902264b445 < d23155634a4bc1183e761d5eb2c043b2e693cc98","Linux >= b46acd6a6a627d876898e1c84d3f84902264b445 < 1200c2779c43b62656ccbb67df9468a7a9af2484","Linux >= b46acd6a6a627d876898e1c84d3f84902264b445 < 2d94ffc9d7b5bb3517b129fe63b52d84bcd4ae56","Linux >= b46acd6a6a627d876898e1c84d3f84902264b445 < 0908da07c23be4f94b99dfd9a94765525f0fe4bd","Linux >= b46acd6a6a627d876898e1c84d3f84902264b445 < 006cb7713dec10368e699abc4367e5faa334c9a5","Linux 5.15"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T22:37:04+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89617.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89617.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89617"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532222"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89617"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89617"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89617.mbox"},{"url":"https://git.kernel.org/stable/c/0e07ea2fc45a7b4757ef7bf1f692cc0180a08323"},{"url":"https://git.kernel.org/stable/c/1e90b1703ee1a04cd3e9e399353fc536f5f3ba10"},{"url":"https://git.kernel.org/stable/c/d23155634a4bc1183e761d5eb2c043b2e693cc98"},{"url":"https://git.kernel.org/stable/c/1200c2779c43b62656ccbb67df9468a7a9af2484"},{"url":"https://git.kernel.org/stable/c/2d94ffc9d7b5bb3517b129fe63b52d84bcd4ae56"},{"url":"https://git.kernel.org/stable/c/0908da07c23be4f94b99dfd9a94765525f0fe4bd"},{"url":"https://git.kernel.org/stable/c/006cb7713dec10368e699abc4367e5faa334c9a5"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00138,"epssPercentile":0.03604,"scores":{"vendor":5.5,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.450Z","slug":"CVE-2026-89617","body":"## Overview\n\nA flaw was found in the Linux kernel's NTFS3 filesystem driver. An attacker with local access could craft a malicious NTFS log file. During log replay, insufficient validation of the `lcns_follow` field in a `DIR_PAGE_ENTRY` could lead to an out-of-bounds write. This memory corruption could result in a system crash (denial of service) or potentially allow for further exploitation.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89617.json)\n\n**kernel: fs/ntfs3: validate dirty page table on log replay** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208072,"id":"CVE-2026-89617","ts":1789922704577,"field":"cvss","old":"7.8","new":"5.5"},{"seq":208071,"id":"CVE-2026-89617","ts":1789922704577,"field":"severity","old":"high","new":"medium"},{"seq":197845,"id":"CVE-2026-89617","ts":1789384320651,"field":"cvss","old":"6.4","new":"7.8"},{"seq":197844,"id":"CVE-2026-89617","ts":1789384320651,"field":"severity","old":"medium","new":"high"},{"seq":183731,"id":"CVE-2026-89617","ts":1789356677141,"field":"cvss","old":"7.8","new":"6.4"},{"seq":183730,"id":"CVE-2026-89617","ts":1789356677141,"field":"severity","old":"high","new":"medium"},{"seq":153452,"id":"CVE-2026-89617","ts":1789285350568,"field":"cvss","old":null,"new":"7.8"},{"seq":153451,"id":"CVE-2026-89617","ts":1789285350568,"field":"severity","old":"none","new":"high"},{"seq":147594,"id":"CVE-2026-89617","ts":1789270211524,"field":"cvss","old":null,"new":"6.4"},{"seq":147593,"id":"CVE-2026-89617","ts":1789270211524,"field":"severity","old":"none","new":"medium"},{"seq":109346,"id":"CVE-2026-89617","ts":1789183731543,"field":"cvss","old":null,"new":"6.4"},{"seq":109345,"id":"CVE-2026-89617","ts":1789183731543,"field":"severity","old":"none","new":"medium"}]}