---
id: CVE-2026-98315
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ntfs: protect runlist updates with the runlist lock

  ntfs_non_resident_attr_shrink() calls runlist helpers that require the
  runlist write lock, but did not hold it whil…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ntfs: protect runlist updates with the runlist lock

  ntfs_non_resident_attr_shrink() calls runlist helpers that require the
  runlist write lock, but did not hold it whil…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 495e90fa334828d4119061e2726af51d0a0fb4ed <
    742797432e8c9b0dd54ecc523c185e26b09d79a0
  - >-
    Linux >= 495e90fa334828d4119061e2726af51d0a0fb4ed <
    91709ba5d6d709b2b663287b7e871e2c6b480502
  - Linux 7.1
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:23.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98315'
references:
  - url: 'https://git.kernel.org/stable/c/742797432e8c9b0dd54ecc523c185e26b09d79a0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/91709ba5d6d709b2b663287b7e871e2c6b480502'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.408Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ntfs: protect runlist updates with the runlist lock

ntfs_non_resident_attr_shrink() calls runlist helpers that require the
runlist write lock, but did not hold it while freeing clusters and
truncating the runlist. Serialize those operations and the resident
conversion with the runlist lock.

ntfs_attr_map_cluster() can merge a newly allocated run before updating
mapping pairs. If the update fails, free the clusters and restore both
the in-memory runlist and on-disk mapping pairs from a saved runlist.
Mark the volume in error if either rollback step fails.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
