---
id: CVE-2026-90133
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib()

  ntfs_ir_to_ib copies all entries from index_root into a freshly allocated
  index_block_size-byte buffer without v…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib()

  ntfs_ir_to_ib copies all entries from index_root into a freshly allocated
  index_block_size-byte buffer without v…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 0a8ac0c1fa0b99a5b29002bc7f232ed7eafddef0 <
    825dec5120933e90c54e30e31ccfa6c3449043a8
  - >-
    Linux >= 0a8ac0c1fa0b99a5b29002bc7f232ed7eafddef0 <
    dc09bf79b76f9a7157e225f449655f3f62f96c9c
  - Linux 7.1
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:43.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90133'
references:
  - url: 'https://git.kernel.org/stable/c/825dec5120933e90c54e30e31ccfa6c3449043a8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dc09bf79b76f9a7157e225f449655f3f62f96c9c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00191
epssPercentile: 0.09006
ingestedAt: '2026-09-17T16:21:47.880Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib()

ntfs_ir_to_ib copies all entries from index_root into a freshly allocated
index_block_size-byte buffer without verifying that the entries fit in the
available space. The entries in index_root may be larger than the usable
entry space in the index block.

This can cause OOB writes past the end of the allocation.

The validator ntfs_index_root_inconsistent() checks that entries are
self-consistent within the IR value, but never cross-checks them against
index_block_size. There is no bounds check in ntfs_ir_to_ib() before the
memcpy.

Fixing this at the sink in ntfs_ir_to_ib() since
ntfs_index_root_inconsistent() validates the logical consistency of
index_root as a structure and a root with large entries is a structurally
valid root. The bug is a size conflict of ntfs_ir_to_ib().
Also, the validator is called once per inode load in
ntfs_read_locked_inode() while ntfs_ir_to_ib() is only called during a
reparent, a check there adds no overhead to the common path.
Moreover, even a future call path that bypasses the validator would still
be protected.

With NULL as first parameter of ntfs_error(), the volume error flag is
never set by this call, so the device name will be absent from the error
message. In any case, that the caller, ntfs_ir_reparent(), prints an error
message that includes the device name on NULL returns.
I think this is the best solution available without adding
'struct super_block *sb' as a parameter to ntfs_ir_to_ib().

This heap out-of-bounds write is triggered by a crafted filesystem image,
which is not in the kernel threat model, anyway, fixing memory errors would
be nice to keep  things secure.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
