External risk intelligence

Linux Kernel NTFS Slab Out-of-Bounds Write

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-90048

The vulnerability exists within the Linux kernel NTFS filesystem driver. Exploitation requires an attacker to provide a specially crafted, loop-mounted NTFS filesystem image. This is a local operation typically requiring physical or authenticated local access to mount filesystems, rather than a network-reachable or public-facing service.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a vulnerability in the Linux kernel's NTFS filesystem driver. The issue involves an out-of-bounds write that could occur when processing a crafted NTFS file, potentially leading to system instability or compromise. The main concern is confirming if this specific driver is in use and if it could be exposed to crafted files.

  • Kernel driver flaw could allow data corruption.
  • Matters if using Linux NTFS filesystem driver.
  • Assess relevance and exposure to crafted files.

Attack Path

How an attacker could exploit the issue

An attacker could trigger this vulnerability by providing a specially crafted, loop-mounted NTFS filesystem image to a system running a vulnerable version of the Linux kernel. When a file within this image is opened and an attribute is added, the kernel's NTFS driver attempts to create a list of these attributes. Due to insufficient checks, this process can write beyond the allocated buffer, potentially leading to a system crash or other unintended consequences.

  • Requires a crafted NTFS image.
  • Triggered by creating file attributes.
  • Can lead to system instability.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to cause a heap buffer overflow when processing a crafted NTFS image. This occurs when attributes within a primary MFT record are expanded beyond the allocated buffer size, potentially leading to system instability or a crash.

  • Linux kernel NTFS filesystem data.
  • Crafted NTFS image mounted locally.
  • System instability or crash.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Linux kernel's NTFS driver is susceptible to a buffer overflow when processing specially crafted NTFS images. This vulnerability could be triggered by local users or processes with the ability to mount filesystems, such as through a loop-mounted image. Responsibility likely falls to infrastructure or platform teams managing the Linux environment, with the first practical step being to identify systems running the affected kernel and assess their exposure, particularly if local users can manipulate mounted filesystems.

  • Kernel developers should own the fix.
  • Verify local file mount privileges.
  • Plan kernel updates in maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel NTFS filesystem driver mentioned in CVE-2026-90048?

This component is part of the Linux kernel that enables the operating system to read, write, and manage files stored on NTFS-formatted drives, which are natively used by Windows systems. It is primarily used when Linux administrators need to mount and interact with external Windows-formatted storage devices or virtual disk images.

What does a slab-out-of-bounds write mean for this vulnerability?

This is a memory safety flaw where the software writes data beyond the intended boundaries of a reserved memory area (the slab). In the context of CVE-2026-90048, the NTFS driver incorrectly calculates the space needed for file attributes, causing it to overwrite adjacent memory. This can lead to system instability, unintended data modification, or a crash.

How can an attacker trigger this buffer overflow?

An attacker must provide a specifically malformed NTFS filesystem image that the system mounts. Simply having a file present on a drive is not enough; the bug is triggered when the kernel driver processes a file's attributes—for example, when an application attempts to create or modify an extended attribute on a file stored within that malicious, mounted image.

Is my system at risk if it does not mount untrusted NTFS images?

According to Halo Surface Signal, this vulnerability is considered very unlikely to be reachable in most environments. Because exploitation typically requires mounting a specially crafted NTFS image, systems that do not perform such operations or restrict the ability to mount external filesystems are significantly less likely to be affected by this specific issue.

What should I do if I am running this kernel component?

Start by auditing your environment to identify systems where the NTFS driver is active and verify who has the authority to mount external filesystems. Since the fix involves kernel-level changes, coordinate with your platform or infrastructure teams to schedule a kernel update during your next standard maintenance cycle.

References