{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  fs/ntfs3: validate ef-\u003esize covers the record's name and value  When an EA record has a non-zero ef-\u003esize, ntfs_read_ea() only checks that the record fits in the remaining buffer (ea_size \u003e bytes), not that ef-\u003esize is large enough to hold the record's own name_len + 1 + elength.  A crafted image can pass validation with, e.g., ef-\u003esize = 24 but elength = 0xffff. ntfs_get_ea() then trusts elength and copies it out of the undersized record, reading past the kmalloc(info-\u003esize) allocation and leaking heap memory to userspace via getxattr():   BUG: KASAN: slab-out-of-bounds in ntfs_get_ea (fs/ntfs3/xattr.c:302)  Read of size 65535 at addr ffff888100794550 by task exploit   __asan_memcpy (mm/kasan/shadow.c:105)   ntfs_get_ea (fs/ntfs3/xattr.c:302)   ntfs_getxattr (fs/ntfs3/xattr.c:848)   __vfs_getxattr (fs/xattr.c:441)   vfs_getxattr (fs/xattr.c:474)   do_getxattr (fs/xattr.c:800)   path_getxattrat (fs/xattr.c:868)   do_syscall_64 (arch/x86/entry/syscall_64.c:94)   The buggy address is located 80 bytes inside of   allocated 84-byte region in cache kmalloc-96  Compute the size the record needs and require ef-\u003esize to cover it.",
  "id": "DEBIAN-CVE-2026-89779",
  "modified": "2026-09-17T04:47:28.407769924Z",
  "published": "2026-09-16T09:17:08.387Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89779"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89779"
  ]
}