CVE-2026-80598

Source
https://cve.org/CVERecord?id=CVE-2026-80598
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80598.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80598
Downstream
Published
2026-08-28T06:48:24Z
Modified
2026-09-01T03:30:47Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ntfs3: fix out-of-bounds read in decompress_lznt
Details

In the Linux kernel, the following vulnerability has been resolved:

ntfs3: fix out-of-bounds read in decompress_lznt

decompress_lznt() does not validate array index bounds before accessing the decompression table. A corrupted NTFS3 image with invalid compressed data can trigger an out-of-bounds read.

Add index bounds checking to prevent the OOB access.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80598.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
522e010b58379fbe19b38fdef5016bca0c3cf405
Fixed
1113fa5b01a47a1a4cdbb9c695197ca6215f02a8
Fixed
61415ffa365d2eca6986914afd0d1412444aa1dd
Fixed
bd77afca2ae9b6d44d37902e3ad672ebb028b070
Fixed
c694f8ea2611e7413b3f04ee47e04a9b7b45817b
Fixed
ff05a98150ebb2b03919a9c05c576681e86abbb7
Fixed
a93980141253c932aa6ae5d4422d90e0162dc774
Fixed
7160a57192fb16d7a6fa9b7f5c7ac341d2444a89

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80598.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80598.json"