← All Advisories

CVE-2026-97437

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97437

Key Details

CVECVE-2026-97437
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e()

The bounds check in ntfs_dir_emit() compares fname->name_len (a

character count) against e->size (a byte count) without accounting

for the 2-byte-per-character UTF-16LE encoding or the ATTR_FILE_NAME

header size:

if (fname->name_len + sizeof(struct NTFS_DE) > le16_to_cpu(e->size))

This computes: name_len + 16 > e_size

The correct check must account for the ATTR_FILE_NAME header (66 bytes

before the name) and the UTF-16LE character size (2 bytes each):

sizeof(NTFS_DE) + offsetof(ATTR_FILE_NAME, name) +

name_len * sizeof(short) > e_size

Which computes: 16 + 66 + name_len * 2 > e_size

The correct calculation already exists as fname_full_size() in ntfs.h

and is used in cmp_fnames(), namei.c, and fslog.c, but was not used

in the readdir path.

A crafted NTFS image with an index entry containing a small e->size

but large fname->name_len bypasses the current check, causing

ntfs_utf16_to_nls() to read past the entry boundary.

Additionally, add a key_size validation in hdr_find_e() to ensure the

declared key_size does not exceed the available entry data, preventing

comparison functions from reading past entry boundaries on the lookup

path. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97437
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97437