{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ntfs: fix off-by-one page overflow in ntfs_decompress()  The per-token range check in ntfs_decompress() uses  \tif (cb \u003e= cb_sb_end || dp_addr \u003e dp_sb_end) \t\tbreak;  so dp_addr == dp_sb_end falls through to the symbol copy `*dp_addr++ = *cb++`, writing one byte past the destination page.  Since NTFS_SB_SIZE == PAGE_SIZE the destination is a single page, so the byte lands in the adjacent page, and *dest_ofs is left one past the sub-block end (the later `*dest_ofs \u0026= ~PAGE_MASK` then yields 1, not 0, so the page is never finalized and later sub-blocks keep writing further past it).  A corrupted compressed $DATA attribute thus produces a bounded run of out-of-bounds writes when the file is read.  Break as soon as dp_addr reaches dp_sb_end; a full sub-block still completes, as its final copy advances dp_addr to exactly dp_sb_end.",
  "id": "DEBIAN-CVE-2026-90118",
  "modified": "2026-09-18T04:47:27.387452094Z",
  "published": "2026-09-17T17:17:03.963Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-90118"
    }
  ],
  "upstream": [
    "CVE-2026-90118"
  ]
}