CVE-2026-90134 PUBLISHED

ntfs: fix kmap_local_page() usage in compress

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

ntfs: fix kmap_local_page() usage in compress

Several compressed I/O paths discard the address returned by kmap_local_page() and later access or unmap the page using page_address(). This is invalid for highmem pages, and local mappings must also be unmapped using the address returned by kmap_local_page().

Map each destination page in ntfs_decompress() only while producing the current sub-block. Use memcpy_from_page(), memcpy_to_page(), and memzero_page() for the other page accesses. Remove unnecessary local mappings from ntfs_write_cb(), where pages are accessed through the vmap() mapping.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 495e90fa334828d4119061e2726af51d0a0fb4ed to 950e2ecc7aec21af24b05bc661a097a81c670409 (excl.)
  • affected from 495e90fa334828d4119061e2726af51d0a0fb4ed to 6e03fbd5f772ad24ea64f7632e4d0d73184787ca (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 7.1 is affected
  • unaffected from 0 to 7.1 (excl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References