CVE-2026-89610Medium· 5.5▾ SunlitA flaw was found in the Linux kernel's NTFS component. The mapping pairs decoder fails to verify if a run length extends beyond the volume boundary. A local attacker could exploit this by providing a malformed NTFS image with a crafted map…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
0.2% → 0.6%
— → 7
none → high
— → 9.8
none → critical
9.8 → 7
critical → high
7 → 9.8
high → critical
9.8 → 7
critical → high
Last analysed / modified upstream
7 → 5.5
high → medium
A flaw was found in the Linux kernel's NTFS component. The mapping pairs decoder fails to verify if a run length extends beyond the volume boundary. A local attacker could exploit this by providing a malformed NTFS image with a crafted mapping pairs array. This could lead to memory corruption and potentially allow for privilege escalation.
kernel: ntfs: verify run length exceeding volume boundary — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.
Not affected:
Refer to the advisory for fix availability.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89436Medium· 5.5kernel: platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[] (CVE-2026-89436)
CVE-2026-89611Medium· 5.5kernel: ntfs: validate non-resident attribute offsets (CVE-2026-89611)
CVE-2026-89612Medium· 5.5kernel: ntfs: reject invalid MFT LCNs from boot sector (CVE-2026-89612)
CVE-2026-89471Medium· 5.5kernel: power: supply: cros_usbpd-charger: bound the EC-reported port count (CVE-2026-89471)
CVE-2026-89513Medium· 5.5kernel: RISC-V: KVM: Fix PMU event info array size overflow (CVE-2026-89513)
CVE-2026-89748Medium· 5.5kernel: tracing: Fix retry exhaustion in simple ring buffer reader swap (CVE-2026-89748)