CVE-2026-89610
A flaw in the Linux kernel’s NTFS file system driver can let a specially crafted NTFS image cause the kernel to read memory beyond the volume’s limits. This can corrupt memory and allow an attacker to gain higher privileges. The issue has been fixed in recent kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users who mount NTFS volumes, especially those using older kernel versions that lack the patch. All distributions that ship the affected kernel.
Real-world impact
An attacker could craft a malicious NTFS image and trick the kernel into reading or writing outside the intended area, corrupting memory and potentially escalating privileges to root.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is exploitable over the network with no authentication, no user interaction, and can compromise confidentiality, integrity, and availability. The vector shows it is a local kernel bug that can lead to full system compromise.
What to do about it
- 011. Update your Linux kernel to a version that includes the patch for CVE-2026-89610.
- 022. Verify that the kernel version is at least the one that contains the fix.
NVD-referenced vendor advisory
Timeline
- Sep 11, 2026 · 2d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 13, 2026 · 6h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.