Answer in brief
CVE-2026-90199 records a Unknown severity vulnerability in fs/ntfs3: reject out-of-range evcn in mi_enum_attr(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=013ff63b649475f0ee134e2c8d0c8e65284ede50 <0441e34ce098c19185a7b52c5b8b89a8a5b26888 || >=013ff63b649475f0ee134e2c8d0c8e65284ede50 <7ab69cef49ebdfee288287d62641b24ab1445ecc || >=013ff63b649475f0ee134e2c8d0c8e65284ede50 <ce9a619c432b9a4044fee115c5483fbed946c131 || >=013ff63b649475f0ee134e2c8d0c8e65284ede50 <2b9a0e57bfd365e2096706b19ae34dce3b4a884b || >=013ff63b649475f0ee134e2c8d0c8e65284ede50 <20fd9f64c0050658f2031e6bd5d552c6f0c8f7e3 || a7accf181a4709a6e380360372150cc4a1b6b89a || 3dfd727873c3e8da74a2e3907120ff052c5f0bcc || 1d7dd485108d4f633b543c9c14071cc325b68ae5 || >=5.15.209 <5.16 || >=6.1.115 <6.2 || >=6.5.11 <6.6 | 0441e34ce098c19185a7b52c5b8b89a8a5b26888, 7ab69cef49ebdfee288287d62641b24ab1445ecc, ce9a619c432b9a4044fee115c5483fbed946c131, 2b9a0e57bfd365e2096706b19ae34dce3b4a884b, 20fd9f64c0050658f2031e6bd5d552c6f0c8f7e3, 5.16, 6.2, 6.6 |
| Linux/Linuxgeneric | 6.6 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject out-of-range evcn in mi_enum_attr() In mi_enum_attr(), the start/end VCN validation for non-resident attributes is: if (svcn > evcn + 1) goto out; When evcn is U64_MAX the "evcn + 1" expression wraps to 0 and any svcn passes the check. For evcn values close to U64_MAX (but not equal to it) the right-hand side is still a meaningless near-wrap upper bound, so a malformed on-disk attribute with svcn == 0 and evcn near U64_MAX can pass mi_enum_attr() unrejected. VCN (virtual cluster number) is a cluster index, so any valid evcn is bounded by the volume's total cluster count, which ntfs3 holds in sbi->used.bitmap.nbits (set up in ntfs_init_from_boot() before any caller of mi_enum_attr() runs). Reject evcn values that fall outside this range. However, an empty non-resident attribute (no allocated clusters) is legitimately encoded with svcn == 0 and evcn == -1 (U64_MAX), e.g. via attr->nres.evcn = cpu_to_le64((u64)vcn - 1) with vcn == 0. That sentinel must keep passing, so exclude evcn == U64_MAX from the range check. The existing "svcn > evcn + 1" test still tolerates the sentinel ("0 > 0" is false) and continues to require svcn == 0 for it, while the range check rejects every other out-of-range evcn and thereby also defuses the "evcn + 1" wraparound. svcn does not need its own bound: once evcn < nbits, "svcn > evcn + 1" implies svcn <= nbits. [[email protected]: fixed evcn check]
Quoted source text, attributed separately from HOL analysis.