External risk intelligence

Linux Kernel NTFS Run Length Memory Corruption

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-89610

This vulnerability exists in the Linux kernel NTFS filesystem driver. Exploitation requires processing a malformed, attacker-supplied NTFS filesystem image. This is not a network-accessible service or web-facing endpoint; it requires local access or the mounting of untrusted storage media, making public internet exposure via this vector very unlikely.

Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A recent vulnerability in the Linux kernel's NTFS file system driver could allow an attacker to corrupt memory and potentially gain elevated privileges by processing a specially crafted NTFS image. While this issue could lead to significant security breaches, its exploitation is unlikely to occur over the public internet as it requires local access or the mounting of untrusted storage. The primary concern is confirming if your systems process such external file system images.

  • A kernel flaw allows data corruption and privilege escalation.
  • Impacts systems processing external NTFS file images.
  • Confirm relevance and exposure to external file systems.

Attack Path

How an attacker could exploit the issue

An attacker could potentially cause memory corruption and elevate their privileges by providing a specially crafted NTFS disk image to a Linux system. The kernel's NTFS driver normally checks if the start of a data mapping is within the disk's boundaries, but it fails to check if the data extends beyond them, allowing it to write to unintended memory locations.

  • Requires processing malformed NTFS image.
  • Vulnerable NTFS mapping pairs decoder.
  • Memory corruption and privilege escalation.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a malicious actor to corrupt memory in the Linux kernel by providing a specially crafted NTFS image. This memory corruption could potentially lead to an attacker gaining elevated privileges on the affected system. This impact is contingent on the system processing a malformed NTFS image, which is a condition that requires specific circumstances to occur.

  • Kernel memory corruption.
  • Processing a malformed NTFS image.
  • Potential privilege escalation.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-World Ownership

This vulnerability impacts the Linux kernel's NTFS filesystem driver, suggesting that infrastructure and platform teams responsible for maintaining the kernel and managing storage are the primary actors. The first practical step involves identifying all systems utilizing the NTFS driver, assessing their business criticality, and confirming if they can process external NTFS images. Once accountable owners are identified, a risk-based remediation plan can be developed.

  • Kernel/Platform teams own the issue.
  • Verify NTFS usage and external mounts.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel NTFS driver?

The NTFS driver is a component within the Linux kernel that allows the operating system to read from and write to storage devices formatted with the Windows New Technology File System (NTFS). It is used when Linux systems need to interact with external drives, dual-boot partitions, or storage media originally created in a Windows environment.

How does CVE-2026-89610 cause memory corruption?

This vulnerability is an out-of-bounds access flaw. When the kernel processes an NTFS image, its mapping pairs decoder verifies that the starting point of a data run is valid but fails to check if the length of that run exceeds the actual physical size of the volume. A malformed image can exploit this to force the kernel to read or write to memory locations outside the intended boundaries, potentially leading to unauthorized privilege escalation.

Do I need to mount a malicious disk to trigger this bug?

Yes. This vulnerability is not triggered by standard network traffic or typical application interactions. It requires the system to actively mount and process a specifically malformed or malicious NTFS filesystem image. Simply having the NTFS driver installed or enabled is not enough to trigger the flaw; the system must attempt to interpret the corrupted data structure within a storage object.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal indicates that this vulnerability is very unlikely to be exploited via public internet-facing vectors. Because the flaw requires processing untrusted storage media or local disk images, it is not considered a remote network-accessible service. You should focus your attention on systems that frequently mount external, unverified, or user-supplied storage devices.

How should I respond to this NTFS kernel flaw?

Begin by identifying which servers or workstations in your environment are configured to use the NTFS driver and verify if they handle external or untrusted media. Prioritize systems where untrusted users can mount their own drives. Once you have an inventory of these high-risk endpoints, coordinate with your platform or infrastructure teams to schedule a kernel update to a patched version.

References