CVE-2026-89612
In the Linux kernel, the following vulnerability has been resolved:
ntfs: reject invalid MFT LCNs from boot sector
The NTFS boot sector stores the MFT and MFTMirr locations as unsigned
64-bit LCNs, but parsentfsboot_sector() decoded them into an s64.
A crafted high-bit value could therefore become negative and pass
the existing upper-bound check. The invalid value then propagated into
the MFT zone allocator and could result in an out-of-bounds access to
lcnemptybitsperpage.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/8f8420b68a6f05ca2b03779d8208814ec539b9e5, https://git.kernel.org/stable/c/cc9d09fef78410bcd37ac05168cbd5f6dd75d3d2, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89612.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89612, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git