---
id: CVE-2026-63833
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ntfs3: reject direct userspace writes to reserved $LX* xattrs

  NTFS3 uses $LXUID, $LXGID, $LXMOD and $LXDEV as internal WSL
  permission metadata and reloads them into i_…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ntfs3: reject direct userspace writes to reserved $LX* xattrs

  NTFS3 uses $LXUID, $LXGID, $LXMOD and $LXDEV as internal WSL
  permission metadata and reloads them into i_…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
published: '2026-07-19'
updated: '2026-08-17'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-63833'
references:
  - url: 'https://git.kernel.org/stable/c/293a84fa40b3a1b3471c0545722724bc10973f76'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2c3cd6da4a14380ef79e34bd9dff7caf46687477'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5b08dccecf825cbf905f348bc6ccb497507e28e2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5e658b9245a52d838ef93729a7bc07de8e19deb7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e574af95234afc3c725988bbc1fdeb46b9f386a4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e8852ae29868e449fdb47eebc28f35fb80741a5f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f8d420949b335a4b51d06ab276beee6b8dfdc909'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00125
epssPercentile: 0.01872
ingestedAt: '2026-08-17T05:47:50.514Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ntfs3: reject direct userspace writes to reserved $LX* xattrs

NTFS3 uses $LXUID, $LXGID, $LXMOD and $LXDEV as internal WSL
permission metadata and reloads them into i_uid, i_gid and i_mode
from ntfs_get_wsl_perm().

Because the empty-prefix xattr handler also lets file owners call
setxattr() on these names directly, an unprivileged writer on a
writable ntfs3 mount can plant root ownership and S_ISUID on their own
file and gain euid 0 after inode reload.

Reject direct userspace writes to the reserved $LX* names. Internal
ntfs3 metadata updates are unchanged because ntfs_save_wsl_perm()
writes them via ntfs_set_ea() directly.

[almaz.alexandrovich@paragon-software.com: added an additional check for non privileged users]

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
