Answer in brief
CVE-2026-63833 records a Unknown severity vulnerability in ntfs3: reject direct userspace writes to reserved $LX* xattrs. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-63833 records a Unknown severity vulnerability in ntfs3: reject direct userspace writes to reserved $LX* xattrs. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <e574af95234afc3c725988bbc1fdeb46b9f386a4 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <2c3cd6da4a14380ef79e34bd9dff7caf46687477 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <e8852ae29868e449fdb47eebc28f35fb80741a5f || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <f8d420949b335a4b51d06ab276beee6b8dfdc909 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <5e658b9245a52d838ef93729a7bc07de8e19deb7 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <293a84fa40b3a1b3471c0545722724bc10973f76 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <5b08dccecf825cbf905f348bc6ccb497507e28e2 | e574af95234afc3c725988bbc1fdeb46b9f386a4, 2c3cd6da4a14380ef79e34bd9dff7caf46687477, e8852ae29868e449fdb47eebc28f35fb80741a5f, f8d420949b335a4b51d06ab276beee6b8dfdc909, 5e658b9245a52d838ef93729a7bc07de8e19deb7, 293a84fa40b3a1b3471c0545722724bc10973f76, 5b08dccecf825cbf905f348bc6ccb497507e28e2 |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ntfs3: reject direct userspace writes to reserved $LX* xattrs NTFS3 uses $LXUID, $LXGID, $LXMOD and $LXDEV as internal WSL permission metadata and reloads them into i_uid, i_gid and i_mode from ntfs_get_wsl_perm(). Because the empty-prefix xattr handler also lets file owners call setxattr() on these names directly, an unprivileged writer on a writable ntfs3 mount can plant root ownership and S_ISUID on their own file and gain euid 0 after inode reload. Reject direct userspace writes to the reserved $LX* names. Internal ntfs3 metadata updates are unchanged because ntfs_save_wsl_perm() writes them via ntfs_set_ea() directly. [[email protected]: added an additional check for non privileged users]
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <e574af95234afc3c725988bbc1fdeb46b9f386a4 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <2c3cd6da4a14380ef79e34bd9dff7caf46687477 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <e8852ae29868e449fdb47eebc28f35fb80741a5f || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <f8d420949b335a4b51d06ab276beee6b8dfdc909 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <5e658b9245a52d838ef93729a7bc07de8e19deb7 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <293a84fa40b3a1b3471c0545722724bc10973f76 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <5b08dccecf825cbf905f348bc6ccb497507e28e2 | e574af95234afc3c725988bbc1fdeb46b9f386a4, 2c3cd6da4a14380ef79e34bd9dff7caf46687477, e8852ae29868e449fdb47eebc28f35fb80741a5f, f8d420949b335a4b51d06ab276beee6b8dfdc909, 5e658b9245a52d838ef93729a7bc07de8e19deb7, 293a84fa40b3a1b3471c0545722724bc10973f76, 5b08dccecf825cbf905f348bc6ccb497507e28e2 |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ntfs3: reject direct userspace writes to reserved $LX* xattrs NTFS3 uses $LXUID, $LXGID, $LXMOD and $LXDEV as internal WSL permission metadata and reloads them into i_uid, i_gid and i_mode from ntfs_get_wsl_perm(). Because the empty-prefix xattr handler also lets file owners call setxattr() on these names directly, an unprivileged writer on a writable ntfs3 mount can plant root ownership and S_ISUID on their own file and gain euid 0 after inode reload. Reject direct userspace writes to the reserved $LX* names. Internal ntfs3 metadata updates are unchanged because ntfs_save_wsl_perm() writes them via ntfs_set_ea() directly. [[email protected]: added an additional check for non privileged users]
Quoted source text, attributed separately from HOL analysis.