{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-31716", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2026-03-09T15:48:24.133Z", "datePublished": "2026-05-01T13:56:11.263Z", "dateUpdated": "2026-08-05T12:24:47.538Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:24:47.538Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate rec->used in journal-replay file record check\n\ncheck_file_record() validates rec->total against the record size but\nnever validates rec->used. The do_action() journal-replay handlers read\nrec->used from disk and use it to compute memmove lengths:\n\n DeleteAttribute: memmove(attr, ..., used - asize - roff)\n CreateAttribute: memmove(..., attr, used - roff)\n change_attr_size: memmove(..., used - PtrOffset(rec, next))\n\nWhen rec->used is smaller than the offset of a validated attribute, or\nlarger than the record size, these subtractions can underflow allowing\nus to copy huge amounts of memory in to a 4kb buffer, generally\nconsidered a bad idea overall.\n\nThis requires a corrupted filesystem, which isn't a threat model the\nkernel really needs to worry about, but checking for such an obvious\nout-of-bounds value is good to keep things robust, especially on journal\nreplay\n\nFix this up by bounding rec->used correctly.\n\nThis is much like commit b2bc7c44ed17 (\"fs/ntfs3: Fix slab-out-of-bounds\nread in DeleteIndexEntryRoot\") which checked different values in this\nsame switch statement." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable ntfs3 journal replay code is reached when the target mounts or otherwise processes a crafted NTFS block device/image, which is a local filesystem parsing path rather than a network protocol. Physical removable media is one delivery route, but local image/block-device mounting is also reasonable.\nAC:L - The attacker controls the corrupt NTFS metadata and journal records, including the `rec->used` value and replay operation needed to trigger the underflowed `memmove()` length. No race or external timing condition is required.\nPR:N - Direct self-triggered mounting is gated by `CAP_SYS_ADMIN` and ntfs3 is not user-namespace mountable, but the highest reasonable scenario is an attacker-supplied NTFS image/media mounted by a victim or automounter. In that scenario the attacker needs no privileges on the target.\nUI:R - Exploitation requires the target system or user to mount/process the crafted NTFS filesystem so journal replay runs. The attacker cannot reach this ntfs3 path solely by sending packets.\nS:U - The impact remains within the same kernel security authority. This is not a VM escape, IOMMU bypass, or cross-scope boundary violation.\nC:H - The bug creates out-of-bounds memory movement from attacker-controlled on-disk metadata into a small MFT record buffer, and the resulting kernel memory corruption/read exposure is not tightly bounded. When uncertain, the higher impact is appropriate.\nI:H - The underflowed `memmove()` length can overflow/corrupt kernel heap memory adjacent to the MFT record buffer. Such out-of-bounds write-style memory corruption is potentially exploitable for arbitrary modification or code execution.\nA:H - The same oversized `memmove()` can cause kernel heap corruption, faults, oopses, or panics during mount-time journal replay. This is a high availability impact." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/ntfs3/fslog.c" ], "versions": [ { "version": "b46acd6a6a627d876898e1c84d3f84902264b445", "lessThan": "8e64d33198b5a0fb14a452708bad844f94f03b2c", "status": "affected", "versionType": "git" }, { "version": "b46acd6a6a627d876898e1c84d3f84902264b445", "lessThan": "1393a467a9607e62123806de7d4c3a3e54e396a9", "status": "affected", "versionType": "git" }, { "version": "b46acd6a6a627d876898e1c84d3f84902264b445", "lessThan": "f90b8a1798b750755a9e9aee66678f0a1820bbaf", "status": "affected", "versionType": "git" }, { "version": "b46acd6a6a627d876898e1c84d3f84902264b445", "lessThan": "4b1613d7e2deda831a97e427d1ea586e50fe1be5", "status": "affected", "versionType": "git" }, { "version": "b46acd6a6a627d876898e1c84d3f84902264b445", "lessThan": "0112e6279420d4005b3d57af36fb45c01b8d0116", "status": "affected", "versionType": "git" }, { "version": "b46acd6a6a627d876898e1c84d3f84902264b445", "lessThan": "f79d0403ea20a81bc29105bba54fbcab54e8c403", "status": "affected", "versionType": "git" }, { "version": "b46acd6a6a627d876898e1c84d3f84902264b445", "lessThan": "0ca0485e4b2e837ebb6cbd4f2451aba665a03e4b", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/ntfs3/fslog.c" ], "versions": [ { "version": "5.15", "status": "affected" }, { "version": "0", "lessThan": "5.15", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.209", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.175", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.136", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.84", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18.25", "lessThanOrEqual": "6.18.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.0.2", "lessThanOrEqual": "7.0.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.1", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "5.15.209" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.1.175" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.6.136" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.12.84" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.18.25" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "7.0.2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "7.1" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/8e64d33198b5a0fb14a452708bad844f94f03b2c" }, { "url": "https://git.kernel.org/stable/c/1393a467a9607e62123806de7d4c3a3e54e396a9" }, { "url": "https://git.kernel.org/stable/c/f90b8a1798b750755a9e9aee66678f0a1820bbaf" }, { "url": "https://git.kernel.org/stable/c/4b1613d7e2deda831a97e427d1ea586e50fe1be5" }, { "url": "https://git.kernel.org/stable/c/0112e6279420d4005b3d57af36fb45c01b8d0116" }, { "url": "https://git.kernel.org/stable/c/f79d0403ea20a81bc29105bba54fbcab54e8c403" }, { "url": "https://git.kernel.org/stable/c/0ca0485e4b2e837ebb6cbd4f2451aba665a03e4b" } ], "title": "fs/ntfs3: validate rec->used in journal-replay file record check", "x_generator": { "engine": "bippy-1.2.0" } } } }