---
id: CVE-2026-89613
title: 'kernel: ntfs: reject invalid empty mapping pairs (CVE-2026-89613)'
summary: >-
  A flaw was found in the Linux kernel's NTFS filesystem driver. This
  vulnerability occurs when the driver processes an attribute with empty mapping
  pairs that have inconsistent highest Virtual Cluster Number (VCN) and size. A
  local attacker…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-130
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4
affected:
  - openshift_container_platform 4
published: '2026-09-11'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T11:02:18+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89613.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89613.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89613'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532432'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89613'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89613'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89613.mbox
  - url: 'https://git.kernel.org/stable/c/766062a82e1ce4087c7dc077224144dfd34b3661'
  - url: 'https://git.kernel.org/stable/c/b0cc6dbc655e037251874b3e0dd1a760dcf29007'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00553
epssPercentile: 0.4483
scores:
  vendor: 4.4
  cna: 9.8
ingestedAt: '2026-09-14T15:23:07.474Z'
---

## Overview

A flaw was found in the Linux kernel's NTFS filesystem driver. This vulnerability occurs when the driver processes an attribute with empty mapping pairs that have inconsistent highest Virtual Cluster Number (VCN) and size. A local attacker could potentially craft a malicious NTFS filesystem that, when mounted, could lead to a denial of service by causing the system to become unresponsive or crash.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89613.json)

**kernel: ntfs: reject invalid empty mapping pairs** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
