fs/ntfs3: reject out-of-range evcn in mi_enum_attr()
Summary
| CVE | CVE-2026-90199 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:17:14 UTC |
| Updated | 2026-09-17 17:17:14 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: reject out-of-range evcn in mi_enum_attr()
In mi_enum_attr(), the start/end VCN validation for non-resident
attributes is:
if (svcn > evcn + 1) goto out;
When evcn is U64_MAX the "evcn + 1" expression wraps to 0 and any svcn
passes the check. For evcn values close to U64_MAX (but not equal to it)
the right-hand side is still a meaningless near-wrap upper bound, so a
malformed on-disk attribute with svcn == 0 and evcn near U64_MAX can pass
mi_enum_attr() unrejected.
VCN (virtual cluster number) is a cluster index, so any valid evcn is
bounded by the volume's total cluster count, which ntfs3 holds in
sbi->used.bitmap.nbits (set up in ntfs_init_from_boot() before any caller
of mi_enum_attr() runs). Reject evcn values that fall outside this range.
However, an empty non-resident attribute (no allocated clusters) is
legitimately encoded with svcn == 0 and evcn == -1 (U64_MAX), e.g. via
attr->nres.evcn = cpu_to_le64((u64)vcn - 1) with vcn == 0. That sentinel
must keep passing, so exclude evcn == U64_MAX from the range check. The
existing "svcn > evcn + 1" test still tolerates the sentinel ("0 > 0" is
false) and continues to require svcn == 0 for it, while the range check
rejects every other out-of-range evcn and thereby also defuses the
"evcn + 1" wraparound.
svcn does not need its own bound: once evcn < nbits, "svcn > evcn + 1"
implies svcn <= nbits.
[[email protected]: fixed evcn check] |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 013ff63b649475f0ee134e2c8d0c8e65284ede50 0441e34ce098c19185a7b52c5b8b89a8a5b26888 git |
Not specified |
| CNA |
Linux |
Linux |
affected 013ff63b649475f0ee134e2c8d0c8e65284ede50 7ab69cef49ebdfee288287d62641b24ab1445ecc git |
Not specified |
| CNA |
Linux |
Linux |
affected 013ff63b649475f0ee134e2c8d0c8e65284ede50 ce9a619c432b9a4044fee115c5483fbed946c131 git |
Not specified |
| CNA |
Linux |
Linux |
affected 013ff63b649475f0ee134e2c8d0c8e65284ede50 2b9a0e57bfd365e2096706b19ae34dce3b4a884b git |
Not specified |
| CNA |
Linux |
Linux |
affected 013ff63b649475f0ee134e2c8d0c8e65284ede50 20fd9f64c0050658f2031e6bd5d552c6f0c8f7e3 git |
Not specified |
| CNA |
Linux |
Linux |
affected a7accf181a4709a6e380360372150cc4a1b6b89a git |
Not specified |
| CNA |
Linux |
Linux |
affected 3dfd727873c3e8da74a2e3907120ff052c5f0bcc git |
Not specified |
| CNA |
Linux |
Linux |
affected 1d7dd485108d4f633b543c9c14071cc325b68ae5 git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.15.209 5.16 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.1.115 6.2 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.5.11 6.6 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.6 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.157 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.52 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.6 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/0441e34ce098c19185a7b52c5b8b89a8a5b26888 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/ce9a619c432b9a4044fee115c5483fbed946c131 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7ab69cef49ebdfee288287d62641b24ab1445ecc |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/20fd9f64c0050658f2031e6bd5d552c6f0c8f7e3 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/2b9a0e57bfd365e2096706b19ae34dce3b4a884b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.