Answer in brief
CVE-2026-64432 records a High severity (CVSS 7.8) vulnerability in fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b46acd6a6a627d876898e1c84d3f84902264b445 <964c3fae1dfc49dde5468eace940f199cda234e9 || >=b46acd6a6a627d876898e1c84d3f84902264b445 <3aa96956ca2200674e2a8f9c23ec6ecd45e5010f || >=b46acd6a6a627d876898e1c84d3f84902264b445 <946046841013ebac8492ef49651c53638d7a9a6a || >=b46acd6a6a627d876898e1c84d3f84902264b445 <c6f9e804f73ef809529865fbc7256dd189ff8c33 || >=b46acd6a6a627d876898e1c84d3f84902264b445 <cf28fc1658463d768657cf1c27a83980d4ba7ef2 || >=b46acd6a6a627d876898e1c84d3f84902264b445 <f433acc85b86f327d03ba8b03a33c105c51053de || >=b46acd6a6a627d876898e1c84d3f84902264b445 <57382ec6ac63b63dce2789e835fded28b698ae79 | 964c3fae1dfc49dde5468eace940f199cda234e9, 3aa96956ca2200674e2a8f9c23ec6ecd45e5010f, 946046841013ebac8492ef49651c53638d7a9a6a, c6f9e804f73ef809529865fbc7256dd189ff8c33, cf28fc1658463d768657cf1c27a83980d4ba7ef2, f433acc85b86f327d03ba8b03a33c105c51053de, 57382ec6ac63b63dce2789e835fded28b698ae79 |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 3, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns In the analysis pass of $LogFile journal replay, log_replay() copies LCNs from each action log record into an existing Dirty Page Table (DPT) entry without bounding the destination index. A crafted NTFS image with DPT entry lcns_follow=1 and an action log record with lcns_follow=2 produces a kernel slab out-of-bounds write at mount time: BUG: KASAN: slab-out-of-bounds in log_replay+0x654c/0xdb60 Write of size 8 at addr ffff8880095e1040 by task mount Two attacker-controlled fields can drive j+i past the allocated page_lcns[] array: 1. dp->lcns_follow (capacity) can be smaller than lrh->lcns_follow. 2. lrh->target_vcn may be smaller than dp->vcn, making the u64 subtraction wrap to a huge size_t. Validate target VCN delta and per-record LCN count against the DPT entry capacity, bail via the existing out: cleanup label with -EINVAL. This mirrors the bounds-check pattern added in commit b2bc7c44ed17 ("fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot") and commit 0ca0485e4b2e ("fs/ntfs3: validate rec->used in journal-replay file record check").
Quoted source text, attributed separately from HOL analysis.