Answer in brief
CVE-2026-64533 records a High severity (CVSS 7.8) vulnerability in fs/ntfs3: validate lcns_follow in log_replay conversion. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b46acd6a6a627d876898e1c84d3f84902264b445 <ca343a99806b4fc8e27c48f08be3445c5fcd1445 || >=b46acd6a6a627d876898e1c84d3f84902264b445 <ddfc8683e1a627dbf1b83bacf8961443dd654258 || >=b46acd6a6a627d876898e1c84d3f84902264b445 <57c071e2c4f30b9c6f5aacb6679aab1269fbae99 || >=b46acd6a6a627d876898e1c84d3f84902264b445 <159f694d682e4215b3822ae31ed3a4631628fe55 || >=b46acd6a6a627d876898e1c84d3f84902264b445 <7adb38279812c9c06b0e3fa7382f4d7887f3fa2d || >=b46acd6a6a627d876898e1c84d3f84902264b445 <32b9f8733feb241627fa5f564b1a99b5cae974c5 || >=b46acd6a6a627d876898e1c84d3f84902264b445 <6a4c53a2e26a865565bd6a460961e8d6fcb32329 | ca343a99806b4fc8e27c48f08be3445c5fcd1445, ddfc8683e1a627dbf1b83bacf8961443dd654258, 57c071e2c4f30b9c6f5aacb6679aab1269fbae99, 159f694d682e4215b3822ae31ed3a4631628fe55, 7adb38279812c9c06b0e3fa7382f4d7887f3fa2d, 32b9f8733feb241627fa5f564b1a99b5cae974c5, 6a4c53a2e26a865565bd6a460961e8d6fcb32329 |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Jul 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate lcns_follow in log_replay conversion log_replay() converts DIR_PAGE_ENTRY_32 records into DIR_PAGE_ENTRY records when replaying version 0 restart tables. During this conversion, the memmove() length is derived directly from the on-disk lcns_follow field: memmove(&dp->vcn, &dp0->vcn_low, 2 * sizeof(u64) + le32_to_cpu(dp->lcns_follow) * sizeof(u64)); check_rstbl() validates restart table structure, but does not constrain per-entry lcns_follow values relative to the entry size. A malformed filesystem image can provide an oversized lcns_follow value, causing the conversion memmove() to access memory beyond the bounds of the allocated restart table buffer. The same field is later used to bound iteration over page_lcns[], so validating lcns_follow during conversion also prevents downstream out-of-bounds access from the same malformed metadata. Compute the maximum valid lcns_follow from the already-validated restart table entry size and reject entries that exceed this bound. Reuse the existing t16/t32 scratch variables already declared in log_replay() to avoid introducing new declarations. [[email protected]: fixed the conflicts]
Quoted source text, attributed separately from HOL analysis.