PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-90048 Linux CVE debrief

A slab-out-of-bounds write vulnerability exists in the Linux kernel's ntfs3 filesystem implementation, specifically in the `ni_create_attr_list` function. This function is called when adding an attribute to a file on an NTFS filesystem, and it can be triggered by a crafted, loop-mounted NTFS image. The vulnerability has been resolved with a patch that sizes the buffer from the actual attributes instead of assuming a single record size is always enough.

Vendor
Linux
Product
Unknown
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-28
Advisory published
2026-09-16
Advisory updated
2026-09-28

Who should care

Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux systems that use the ntfs3 filesystem implementation should be aware of this vulnerability and take steps to verify patch application and monitor for suspicious activity.

Why it matters

A slab-out-of-bounds write vulnerability exists in the Linux kernel's ntfs3 filesystem implementation. This vulnerability can be triggered by a crafted, loop-mounted NTFS image and has been resolved with a patch.

  • Verify patch application and kernel version
  • Restrict access to NTFS filesystems
  • Monitor for suspicious activity

Technical summary

The `ni_create_attr_list` function in the Linux kernel's ntfs3 filesystem implementation does not properly check the size of the buffer when adding attributes to a file. This can lead to a slab-out-of-bounds write vulnerability when a crafted, loop-mounted NTFS image is used. The patch addresses this issue by sizing the buffer from the actual attributes instead of assuming a single record size is always enough. This change prevents the slab-out-of-bounds write vulnerability by ensuring the buffer is large enough to hold all attributes.

Defensive priority

High

Recommended defensive actions

  • Review and apply the patch to the Linux kernel's ntfs3 filesystem implementation
  • Restrict access to NTFS filesystems to trusted sources
  • Monitor for suspicious activity on NTFS filesystems
  • Verify patch application and kernel version
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability was discovered in the Linux kernel's ntfs3 filesystem implementation. A crafted, loop-mounted NTFS image can trigger the vulnerability. The patch sizes the buffer from the actual attributes instead of assuming a single record size is always enough. Defenders should verify patch application, kernel version, and monitor for suspicious activity on NTFS filesystems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-90048 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-90048

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-90048 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90048

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7c4841e2a62794a3bab7c1ff0540580f387e377f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7e9aee7e4d9767cc3e423b3beecb01c7ebb6bbcd

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a84f3db72561c4d9281c5ff721ce46b9ffa7f30e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d07e281f2a7710502985d6f80b95ddac8f4e81d5

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/fa2215cf451414b0512cd6f7d37a057893811f4d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.