---
id: CVE-2026-90199
title: "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: reject out-of-range evcn in mi_enum_attr()\n\nIn mi_enum_attr(), the start/end VCN validation for non-resident\nattributes is:\n\n\tif (svcn > evcn + 1) goto out;\n\n…"
summary: "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: reject out-of-range evcn in mi_enum_attr()\n\nIn mi_enum_attr(), the start/end VCN validation for non-resident\nattributes is:\n\n\tif (svcn > evcn + 1) goto out;\n\n…"
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 013ff63b649475f0ee134e2c8d0c8e65284ede50 <
    0441e34ce098c19185a7b52c5b8b89a8a5b26888
  - >-
    Linux >= 013ff63b649475f0ee134e2c8d0c8e65284ede50 <
    7ab69cef49ebdfee288287d62641b24ab1445ecc
  - >-
    Linux >= 013ff63b649475f0ee134e2c8d0c8e65284ede50 <
    ce9a619c432b9a4044fee115c5483fbed946c131
  - >-
    Linux >= 013ff63b649475f0ee134e2c8d0c8e65284ede50 <
    2b9a0e57bfd365e2096706b19ae34dce3b4a884b
  - >-
    Linux >= 013ff63b649475f0ee134e2c8d0c8e65284ede50 <
    20fd9f64c0050658f2031e6bd5d552c6f0c8f7e3
  - Linux a7accf181a4709a6e380360372150cc4a1b6b89a
  - Linux 3dfd727873c3e8da74a2e3907120ff052c5f0bcc
  - Linux 1d7dd485108d4f633b543c9c14071cc325b68ae5
  - Linux >= 5.15.209 < 5.16
  - Linux >= 6.1.115 < 6.2
  - Linux >= 6.5.11 < 6.6
  - Linux 6.6
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:45.950'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90199'
references:
  - url: 'https://git.kernel.org/stable/c/0441e34ce098c19185a7b52c5b8b89a8a5b26888'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/20fd9f64c0050658f2031e6bd5d552c6f0c8f7e3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2b9a0e57bfd365e2096706b19ae34dce3b4a884b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7ab69cef49ebdfee288287d62641b24ab1445ecc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ce9a619c432b9a4044fee115c5483fbed946c131'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00174
epssPercentile: 0.0712
ingestedAt: '2026-09-17T16:21:47.861Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: reject out-of-range evcn in mi_enum_attr()

In mi_enum_attr(), the start/end VCN validation for non-resident
attributes is:

	if (svcn > evcn + 1) goto out;

When evcn is U64_MAX the "evcn + 1" expression wraps to 0 and any svcn
passes the check. For evcn values close to U64_MAX (but not equal to it)
the right-hand side is still a meaningless near-wrap upper bound, so a
malformed on-disk attribute with svcn == 0 and evcn near U64_MAX can pass
mi_enum_attr() unrejected.

VCN (virtual cluster number) is a cluster index, so any valid evcn is
bounded by the volume's total cluster count, which ntfs3 holds in
sbi->used.bitmap.nbits (set up in ntfs_init_from_boot() before any caller
of mi_enum_attr() runs). Reject evcn values that fall outside this range.

However, an empty non-resident attribute (no allocated clusters) is
legitimately encoded with svcn == 0 and evcn == -1 (U64_MAX), e.g. via
attr->nres.evcn = cpu_to_le64((u64)vcn - 1) with vcn == 0. That sentinel
must keep passing, so exclude evcn == U64_MAX from the range check. The
existing "svcn > evcn + 1" test still tolerates the sentinel ("0 > 0" is
false) and continues to require svcn == 0 for it, while the range check
rejects every other out-of-range evcn and thereby also defuses the
"evcn + 1" wraparound.

svcn does not need its own bound: once evcn < nbits, "svcn > evcn + 1"
implies svcn <= nbits.

[almaz.alexandrovich@paragon-software.com: fixed evcn check]

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
