CVE-2026-89779
- Gepubliceerd16 sep 2026
Beschrijving
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's name and value When an EA record has a non-zero ef->size, ntfs_read_ea() only checks that the record fits in the remaining buffer (ea_size > bytes), not that ef->size is large enough to hold the record's own name_len + 1 + elength. A crafted image can pass validation with, e.g., ef->size = 24 but elength = 0xffff. ntfs_get_ea() then trusts elength and copies it out of the undersized record, reading past the kmalloc(info->size) allocation and leaking heap memory to userspace via getxattr(): BUG: KASAN: slab-out-of-bounds in ntfs_get_ea (fs/ntfs3/xattr.c:302) Read of size 65535 at addr ffff888100794550 by task exploit __asan_memcpy (mm/kasan/shadow.c:105) ntfs_get_ea (fs/ntfs3/xattr.c:302) ntfs_getxattr (fs/ntfs3/xattr.c:848) __vfs_getxattr (fs/xattr.c:441) vfs_getxattr (fs/xattr.c:474) do_getxattr (fs/xattr.c:800) path_getxattrat (fs/xattr.c:868) do_syscall_64 (arch/x86/entry/syscall_64.c:94) The buggy address is located 80 bytes inside of allocated 84-byte region in cache kmalloc-96 Compute the size the record needs and require ef->size to cover it.
CVSS 3.1-ontleding
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HHerstel
Er is geen opgeloste versie vastgelegd in de NVD-data. Raadpleeg het leveranciersadvies voor de laatste richtlijnen.
Referenties
- https://git.kernel.org/stable/c/077df8464cf24f8ffc82fb6efec2ae600686e699
- https://git.kernel.org/stable/c/28a924c7e67e6d71abeb04860b61166fecb027fc
- https://git.kernel.org/stable/c/aab1880058ac767d3ea9388a9a7221c776c22c44
- https://git.kernel.org/stable/c/b27e68ad818a4ca2cef8f35f97e75d756714c818
- https://git.kernel.org/stable/c/c22f91d82cb9a29d22bdffdce6c803467984ad0c
- https://git.kernel.org/stable/c/c8a109c9e23a2c7fd548473dde728b2cb8188146
- https://git.kernel.org/stable/c/d585ed08308909c7e6fefb4e8a258aeb29b19ff9
Veelgestelde vragen
Wordt CVE-2026-89779 actief misbruikt?
CVE-2026-89779 staat niet in de CISA KEV-catalogus. De EPSS-exploitkans is 0.21%.
Hoe ernstig is CVE-2026-89779?
CVE-2026-89779 heeft een CVSS 3.1-basisscore van 9.1, beoordeeld als critical. EPSS schat een exploitkans van 0.21%.
Hoe verhelp ik CVE-2026-89779?
Pas de patch of het advies van de leverancier toe en controleer dat er geen getroffen versies meer op uw apparaten staan.
Hoe Secuno hiermee omgaat
Secuno correleert kwetsbaarheden zoals CVE-2026-89779 dagelijks tegen de werkelijke software-inventaris op elk beheerd apparaat. In plaats van een statische ernst wordt elke match in context gescoord: exploitbeschikbaarheid, EPSS, de blootstelling van het asset en bedrijfskriticiteit bepalen de prioriteit. Als een getroffen versie ergens in uw portfolio aanwezig is, verschijnt die automatisch met een geprioriteerd hersteltraject.
Data uit de NVD, CISA KEV-catalogus en FIRST EPSS. CVSS 3.1-basisscore getoond indien beschikbaar.