PatchSiren cyber security CVE debrief
CVE-2026-90048 Linux CVE debrief
A slab-out-of-bounds write vulnerability exists in the Linux kernel's ntfs3 filesystem implementation, specifically in the `ni_create_attr_list` function. This function is called when adding an attribute to a file on an NTFS filesystem, and it can be triggered by a crafted, loop-mounted NTFS image. The vulnerability has been resolved with a patch that sizes the buffer from the actual attributes instead of assuming a single record size is always enough.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-28
Who should care
Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux systems that use the ntfs3 filesystem implementation should be aware of this vulnerability and take steps to verify patch application and monitor for suspicious activity.
Why it matters
A slab-out-of-bounds write vulnerability exists in the Linux kernel's ntfs3 filesystem implementation. This vulnerability can be triggered by a crafted, loop-mounted NTFS image and has been resolved with a patch.
- Verify patch application and kernel version
- Restrict access to NTFS filesystems
- Monitor for suspicious activity
Technical summary
The `ni_create_attr_list` function in the Linux kernel's ntfs3 filesystem implementation does not properly check the size of the buffer when adding attributes to a file. This can lead to a slab-out-of-bounds write vulnerability when a crafted, loop-mounted NTFS image is used. The patch addresses this issue by sizing the buffer from the actual attributes instead of assuming a single record size is always enough. This change prevents the slab-out-of-bounds write vulnerability by ensuring the buffer is large enough to hold all attributes.
Defensive priority
High
Recommended defensive actions
- Review and apply the patch to the Linux kernel's ntfs3 filesystem implementation
- Restrict access to NTFS filesystems to trusted sources
- Monitor for suspicious activity on NTFS filesystems
- Verify patch application and kernel version
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability was discovered in the Linux kernel's ntfs3 filesystem implementation. A crafted, loop-mounted NTFS image can trigger the vulnerability. The patch sizes the buffer from the actual attributes instead of assuming a single record size is always enough. Defenders should verify patch application, kernel version, and monitor for suspicious activity on NTFS filesystems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-90048 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-90048
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-90048 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90048
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7c4841e2a62794a3bab7c1ff0540580f387e377f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7e9aee7e4d9767cc3e423b3beecb01c7ebb6bbcd
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a84f3db72561c4d9281c5ff721ce46b9ffa7f30e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d07e281f2a7710502985d6f80b95ddac8f4e81d5
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/fa2215cf451414b0512cd6f7d37a057893811f4d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.