{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "82cae269cfa953032fbb8980a7d554d60fb00b17"
            },
            {
              "fixed": "a8f4fb6a7d58974ffc9aed597401528b181d76dc"
            },
            {
              "fixed": "0257e3ea00e19129f3ad5c039d8b8fdff0796835"
            },
            {
              "fixed": "98d6e5d9dc1d34dcffc61549617581a5fe1ef807"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "5.15.0"
            },
            {
              "fixed": "6.12.111"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.53"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97438.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate index entry key bounds\n\n[BUG]\nA malformed NTFS directory index entry can advertise a key_size larger\nthan the bytes actually present in its NTFS_DE payload. Directory lookup\nthen passes that malformed key to cmp_fnames(), which can read past the\nend of the kmalloc'ed index buffer.\n\nBUG: KASAN: slab-out-of-bounds in fname_full_size fs/ntfs3/ntfs.h:590 [inline]\nBUG: KASAN: slab-out-of-bounds in cmp_fnames+0x1ea/0x230 fs/ntfs3/index.c:46\nRead of size 1 at addr ffff88801c313018 by task syz.6.3365/9279\n\nCall Trace:\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0xbe/0x130 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xd1/0x650 mm/kasan/report.c:482\n kasan_report+0xfb/0x140 mm/kasan/report.c:595\n __asan_report_load1_noabort+0x14/0x30 mm/kasan/report_generic.c:378\n fname_full_size fs/ntfs3/ntfs.h:590 [inline]\n cmp_fnames+0x1ea/0x230 fs/ntfs3/index.c:46\n hdr_find_e.isra.0+0x3ed/0x670 fs/ntfs3/index.c:762\n indx_find+0x4b5/0x900 fs/ntfs3/index.c:1186\n dir_search_u+0x2c0/0x460 fs/ntfs3/dir.c:254\n ntfs_lookup+0x1cc/0x2a0 fs/ntfs3/namei.c:85\n __lookup_slow+0x241/0x450 fs/namei.c:1816\n lookup_slow fs/namei.c:1833 [inline]\n walk_component+0x31c/0x570 fs/namei.c:2151\n link_path_walk+0x592/0xd60 fs/namei.c:2519\n path_lookupat+0x138/0x660 fs/namei.c:2675\n filename_lookup+0x1f3/0x560 fs/namei.c:2705\n filename_setxattr+0xad/0x1c0 fs/xattr.c:660\n path_setxattrat+0x1d8/0x280 fs/xattr.c:713\n __do_sys_lsetxattr fs/xattr.c:754 [inline]\n __se_sys_lsetxattr fs/xattr.c:750 [inline]\n __x64_sys_lsetxattr+0xd0/0x150 fs/xattr.c:750\n ...\n\nAllocated by task 9279:\n kasan_save_stack+0x39/0x70 mm/kasan/common.c:56\n kasan_save_track+0x14/0x40 mm/kasan/common.c:77\n kasan_save_alloc_info+0x37/0x60 mm/kasan/generic.c:573\n poison_kmalloc_redzone mm/kasan/common.c:400 [inline]\n __kasan_kmalloc+0xc3/0xd0 mm/kasan/common.c:417\n kasan_kmalloc include/linux/kasan.h:262 [inline]\n __do_kmalloc_node mm/slub.c:5650 [inline]\n __kmalloc_noprof+0x2bd/0x900 mm/slub.c:5662\n kmalloc_noprof include/linux/slab.h:961 [inline]\n indx_read+0x41d/0xad0 fs/ntfs3/index.c:1059\n indx_find+0x447/0x900 fs/ntfs3/index.c:1179\n dir_search_u+0x2c0/0x460 fs/ntfs3/dir.c:254\n ntfs_lookup+0x1cc/0x2a0 fs/ntfs3/namei.c:85\n __lookup_slow+0x241/0x450 fs/namei.c:1816\n lookup_slow fs/namei.c:1833 [inline]\n walk_component+0x31c/0x570 fs/namei.c:2151\n link_path_walk+0x592/0xd60 fs/namei.c:2519\n path_lookupat+0x138/0x660 fs/namei.c:2675\n filename_lookup+0x1f3/0x560 fs/namei.c:2705\n filename_setxattr+0xad/0x1c0 fs/xattr.c:660\n path_setxattrat+0x1d8/0x280 fs/xattr.c:713\n __do_sys_lsetxattr fs/xattr.c:754 [inline]\n __se_sys_lsetxattr fs/xattr.c:750 [inline]\n __x64_sys_lsetxattr+0xd0/0x150 fs/xattr.c:750\n ...\n\n[CAUSE]\nThe index-header validators only validated INDEX_HDR-level geometry.\nThey did not walk each NTFS_DE to verify entry alignment, subnode\nlayout, or that key_size fit inside the entry payload. They also\nallowed a last sentinel entry to carry a non-zero key_size.\n\n[FIX]\nWalk every NTFS_DE in ntfs3's index-header validators and reject\nentries with invalid layout, mismatched subnode state, oversized\nkey_size, or non-zero sentinel keys before lookup or log replay can\nconsume them.",
  "id": "CVE-2026-97438",
  "modified": "2026-09-26T03:30:22.245827285Z",
  "published": "2026-09-24T16:03:51.466Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0257e3ea00e19129f3ad5c039d8b8fdff0796835"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/98d6e5d9dc1d34dcffc61549617581a5fe1ef807"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/a8f4fb6a7d58974ffc9aed597401528b181d76dc"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97438.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97438"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "fs/ntfs3: validate index entry key bounds"
}