Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-80674

ntfs: validate resident attribute lists and harden the validator
Back to all
CVE

CVE-2026-80674

ntfs: validate resident attribute lists and harden the validator

In the Linux kernel, the following vulnerability has been resolved:

ntfs: validate resident attribute lists and harden the validator

A base inode's $ATTRIBUTELIST is sanity-checked by loadattribute_list()

only on the non-resident path; ntfsreadlocked_inode() copies a resident

attribute list into ni->attr_list with a plain memcpy() and no validation

at all. Every subsequent walk of ni->attr_list --

ntfsexternalattrfind(), ntfsinodeattachall_extents() and

ntfsattrlistneed() -- then trusts the entries are well-formed and reads

attrlistentry fixed-header fields

(lowestvcn at offset 8, mftreference at offset 16, and the name) with

bounds that assume validation already happened. A crafted resident

attribute list therefore reaches those walks unvalidated and can drive

out-of-bounds reads of the attribute-list buffer.

loadattributelist() itself reads ale->name_offset (offset 7),

ale->mft_reference (offset 16) and the name length under only an

"al < al_start + size" bound, so its own validation loop can over-read the

fixed header of a truncated trailing entry by a few bytes.

Factor the per-entry validation into ntfsattrlistentryis_valid(),

which requires each entry's fixed header (offsetof(struct

attrlistentry, name)) to be in range before any field is dereferenced,

that ale->length is a multiple of 8 covering the fixed header plus the

name, and that the entry is in use and carries a live MFT reference.

ntfsattrlistisvalid() walks the buffer with it and checks the entries

tile it exactly. Use the list validator in loadattributelist()

(replacing the open-coded loop, closing its own over-read) and on the

resident path in ntfsreadlocked_inode() (which previously skipped

validation entirely); patches 2/3 reuse the per-entry helper at the other

two attribute-list walks.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/55e97648f7753c6097cb682d24d1abcfe878e812, https://git.kernel.org/stable/c/7d19e1ffee084c4f7d321a360c14ba43404f7cc8, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80674.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80674, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00553%
EPSS Percentile
0.44474%
Introduced Version
1e9ea7e04472d4e5e12e58c881eaacfb3e49b669,7.1.0,0
Fix Available
7d19e1ffee084c4f7d321a360c14ba43404f7cc8,7.1.5

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading