Answer in brief
CVE-2026-89779 records a Unknown severity vulnerability in fs/ntfs3: validate ef->size covers the record's name and value. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=333feb7ba84f69f9b423422417aaac54fd9e7c84 <b27e68ad818a4ca2cef8f35f97e75d756714c818 || >=000a9a72efa4a9df289bab9c9e8ba1639c72e0d6 <28a924c7e67e6d71abeb04860b61166fecb027fc || >=0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b <d585ed08308909c7e6fefb4e8a258aeb29b19ff9 || >=0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b <077df8464cf24f8ffc82fb6efec2ae600686e699 || >=0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b <aab1880058ac767d3ea9388a9a7221c776c22c44 || >=0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b <c8a109c9e23a2c7fd548473dde728b2cb8188146 || >=0e8235d28f3a0e9eda9f02ff67ee566d5f42b66b <c22f91d82cb9a29d22bdffdce6c803467984ad0c || >=5.15.121 <5.15.221 || >=6.1.40 <6.1.188 | b27e68ad818a4ca2cef8f35f97e75d756714c818, 28a924c7e67e6d71abeb04860b61166fecb027fc, d585ed08308909c7e6fefb4e8a258aeb29b19ff9, 077df8464cf24f8ffc82fb6efec2ae600686e699, aab1880058ac767d3ea9388a9a7221c776c22c44, c8a109c9e23a2c7fd548473dde728b2cb8188146, c22f91d82cb9a29d22bdffdce6c803467984ad0c, 5.15.221, 6.1.188 |
| Linux/Linuxgeneric | 6.2 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's name and value When an EA record has a non-zero ef->size, ntfs_read_ea() only checks that the record fits in the remaining buffer (ea_size > bytes), not that ef->size is large enough to hold the record's own name_len + 1 + elength. A crafted image can pass validation with, e.g., ef->size = 24 but elength = 0xffff. ntfs_get_ea() then trusts elength and copies it out of the undersized record, reading past the kmalloc(info->size) allocation and leaking heap memory to userspace via getxattr(): BUG: KASAN: slab-out-of-bounds in ntfs_get_ea (fs/ntfs3/xattr.c:302) Read of size 65535 at addr ffff888100794550 by task exploit __asan_memcpy (mm/kasan/shadow.c:105) ntfs_get_ea (fs/ntfs3/xattr.c:302) ntfs_getxattr (fs/ntfs3/xattr.c:848) __vfs_getxattr (fs/xattr.c:441) vfs_getxattr (fs/xattr.c:474) do_getxattr (fs/xattr.c:800) path_getxattrat (fs/xattr.c:868) do_syscall_64 (arch/x86/entry/syscall_64.c:94) The buggy address is located 80 bytes inside of allocated 84-byte region in cache kmalloc-96 Compute the size the record needs and require ef->size to cover it.
Quoted source text, attributed separately from HOL analysis.