Skip to main content

In the Linux kernel, the following vulnerability has been resolved: ntfs: verify run length exceeding volume boundary The mapping pairs decoder… (CVE-2026-89610)

0
High
Published: 09/11/2026 (09/11/2026, 21:31:33 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's NTFS mapping pairs decoder has been resolved. The flaw involved improper validation of run length, allowing a run to extend beyond the volume boundary. This could lead to memory corruption and privilege escalation if a malformed NTFS image is processed. The fix adds validation to ensure the logical cluster number plus the run length stays within the volume's cluster count.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 01:02:15 UTC

Technical Analysis

The Linux kernel's NTFS mapping pairs decoder previously validated that the starting logical cluster number (LCN) was within the volume boundary but did not verify that the run length did not exceed the volume boundary. This allowed a crafted NTFS image with a malicious mapping pairs array to cause the kernel to access memory beyond the volume boundary, potentially resulting in memory corruption and privilege escalation. The vulnerability has been addressed by adding validation to ensure that the sum of the LCN and run length remains within the total number of clusters in the volume.

Potential Impact

An attacker who can supply a specially crafted NTFS image could exploit this vulnerability to cause the kernel to access memory outside the intended volume boundary. This may lead to memory corruption and privilege escalation, potentially allowing unauthorized code execution or system compromise.

Mitigation Recommendations

A fix has been implemented in the Linux kernel to add proper validation of the run length in the NTFS mapping pairs decoder. Users and administrators should apply the official kernel updates that include this patch to remediate the vulnerability. No additional mitigations are specified.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-whjw-7h99-rmg2
Osv Schema Version
1.4.0
Aliases
["CVE-2026-89610"]

Threat ID: 6aa4a00b55bf5e2cf5a8666d

Added to database: 09/12/2026, 00:42:51 UTC

Last enriched: 09/12/2026, 01:02:15 UTC

Last updated: 09/12/2026, 01:02:15 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses