In the Linux kernel, the following vulnerability has been resolved: ntfs: verify run length exceeding volume boundary The mapping pairs decoder… (CVE-2026-89610)
A vulnerability in the Linux kernel's NTFS mapping pairs decoder has been resolved. The flaw involved improper validation of run length, allowing a run to extend beyond the volume boundary. This could lead to memory corruption and privilege escalation if a malformed NTFS image is processed. The fix adds validation to ensure the logical cluster number plus the run length stays within the volume's cluster count.
AI Analysis
Technical Summary
The Linux kernel's NTFS mapping pairs decoder previously validated that the starting logical cluster number (LCN) was within the volume boundary but did not verify that the run length did not exceed the volume boundary. This allowed a crafted NTFS image with a malicious mapping pairs array to cause the kernel to access memory beyond the volume boundary, potentially resulting in memory corruption and privilege escalation. The vulnerability has been addressed by adding validation to ensure that the sum of the LCN and run length remains within the total number of clusters in the volume.
Potential Impact
An attacker who can supply a specially crafted NTFS image could exploit this vulnerability to cause the kernel to access memory outside the intended volume boundary. This may lead to memory corruption and privilege escalation, potentially allowing unauthorized code execution or system compromise.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to add proper validation of the run length in the NTFS mapping pairs decoder. Users and administrators should apply the official kernel updates that include this patch to remediate the vulnerability. No additional mitigations are specified.
In the Linux kernel, the following vulnerability has been resolved: ntfs: verify run length exceeding volume boundary The mapping pairs decoder… (CVE-2026-89610)
Description
A vulnerability in the Linux kernel's NTFS mapping pairs decoder has been resolved. The flaw involved improper validation of run length, allowing a run to extend beyond the volume boundary. This could lead to memory corruption and privilege escalation if a malformed NTFS image is processed. The fix adds validation to ensure the logical cluster number plus the run length stays within the volume's cluster count.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's NTFS mapping pairs decoder previously validated that the starting logical cluster number (LCN) was within the volume boundary but did not verify that the run length did not exceed the volume boundary. This allowed a crafted NTFS image with a malicious mapping pairs array to cause the kernel to access memory beyond the volume boundary, potentially resulting in memory corruption and privilege escalation. The vulnerability has been addressed by adding validation to ensure that the sum of the LCN and run length remains within the total number of clusters in the volume.
Potential Impact
An attacker who can supply a specially crafted NTFS image could exploit this vulnerability to cause the kernel to access memory outside the intended volume boundary. This may lead to memory corruption and privilege escalation, potentially allowing unauthorized code execution or system compromise.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to add proper validation of the run length in the NTFS mapping pairs decoder. Users and administrators should apply the official kernel updates that include this patch to remediate the vulnerability. No additional mitigations are specified.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-whjw-7h99-rmg2
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-89610"]
Threat ID: 6aa4a00b55bf5e2cf5a8666d
Added to database: 09/12/2026, 00:42:51 UTC
Last enriched: 09/12/2026, 01:02:15 UTC
Last updated: 09/12/2026, 01:02:15 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.