CVE-2026-64432

Source
https://cve.org/CVERecord?id=CVE-2026-64432
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64432.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64432
Downstream
Published
2026-07-25T08:51:07.791Z
Modified
2026-07-28T04:03:05.202504269Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns
Details

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: validate Dirty Page Table capacity in logreplay copylcns

In the analysis pass of $LogFile journal replay, logreplay() copies LCNs from each action log record into an existing Dirty Page Table (DPT) entry without bounding the destination index. A crafted NTFS image with DPT entry lcnsfollow=1 and an action log record with lcns_follow=2 produces a kernel slab out-of-bounds write at mount time:

BUG: KASAN: slab-out-of-bounds in log_replay+0x654c/0xdb60 Write of size 8 at addr ffff8880095e1040 by task mount

Two attacker-controlled fields can drive j+i past the allocated page_lcns[] array:

  1. dp->lcnsfollow (capacity) can be smaller than lrh->lcnsfollow.
  2. lrh->targetvcn may be smaller than dp->vcn, making the u64 subtraction wrap to a huge sizet.

Validate target VCN delta and per-record LCN count against the DPT entry capacity, bail via the existing out: cleanup label with -EINVAL.

This mirrors the bounds-check pattern added in commit b2bc7c44ed17 ("fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot") and commit 0ca0485e4b2e ("fs/ntfs3: validate rec->used in journal-replay file record check").

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64432.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b46acd6a6a627d876898e1c84d3f84902264b445
Fixed
964c3fae1dfc49dde5468eace940f199cda234e9
Fixed
3aa96956ca2200674e2a8f9c23ec6ecd45e5010f
Fixed
946046841013ebac8492ef49651c53638d7a9a6a
Fixed
c6f9e804f73ef809529865fbc7256dd189ff8c33
Fixed
cf28fc1658463d768657cf1c27a83980d4ba7ef2
Fixed
f433acc85b86f327d03ba8b03a33c105c51053de
Fixed
57382ec6ac63b63dce2789e835fded28b698ae79

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64432.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64432.json"