Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

In the Linux kernel, the following vulnerability has been resolved: ntfs: avoid calling post_write_mst_fixup() for invalid index_block… (CVE-2026-64431)

0
Medium
Published: 07/25/2026 (07/25/2026, 12:31:35 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's NTFS driver involved improper handling of invalid index_block data during write operations. The function ntfs_icx_ib_sync_write() called post_write_mst_fixup() even when pre_write_mst_fixup() validation failed, leading to out-of-bounds memory access. This could be triggered by a crafted NTFS image with manipulated index_block parameters causing memory corruption. The issue has been resolved by moving the post_write_mst_fixup() call to ntfs_ib_write(), ensuring it is only called when pre_write_mst_fixup() succeeds.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/25/2026, 23:24:27 UTC

Technical Analysis

The Linux kernel NTFS driver had a vulnerability where ntfs_icx_ib_sync_write() called post_write_mst_fixup() after ntfs_ib_write() returned an error, without distinguishing between I/O errors and validation failures. Since post_write_mst_fixup() assumes valid index_block contents and does not perform boundary checks, this led to out-of-bounds memory access when the index_block was invalid. An attacker could craft a malicious NTFS image with large or malformed index_block.usa_ofs and usa_count values to trigger this memory corruption. The fix moves the post_write_mst_fixup() call into ntfs_ib_write(), preventing calls on invalid index_block data.

Potential Impact

The vulnerability causes out-of-bounds memory access in kernel space, which can lead to memory corruption. Although no specific exploit in the wild is known, this type of flaw could potentially be leveraged for denial of service or privilege escalation if exploited. The impact is limited to systems mounting or writing to malicious NTFS images.

Mitigation Recommendations

A fix has been implemented in the Linux kernel by relocating the post_write_mst_fixup() call to ntfs_ib_write(), ensuring it is only invoked after successful pre_write_mst_fixup() validation. Users should apply the updated Linux kernel version containing this fix. Patch status is not explicitly stated here; check the vendor or kernel mailing list advisories for the exact fixed kernel versions and apply updates accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-7v8v-8486-fvc6
Osv Schema Version
1.4.0
Aliases
["CVE-2026-64431"]
Ecosystems
[]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a6542099c2644c7f80838c0

Added to database: 07/25/2026, 23:08:57 UTC

Last enriched: 07/25/2026, 23:24:27 UTC

Last updated: 07/26/2026, 03:44:35 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses