CVE-2026-90199 PUBLISHED

fs/ntfs3: reject out-of-range evcn in mi_enum_attr()

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: reject out-of-range evcn in mi_enum_attr()

In mi_enum_attr(), the start/end VCN validation for non-resident attributes is:

<pre>if (svcn > evcn + 1) goto out; </pre>

When evcn is U64_MAX the "evcn + 1" expression wraps to 0 and any svcn passes the check. For evcn values close to U64_MAX (but not equal to it) the right-hand side is still a meaningless near-wrap upper bound, so a malformed on-disk attribute with svcn == 0 and evcn near U64_MAX can pass mi_enum_attr() unrejected.

VCN (virtual cluster number) is a cluster index, so any valid evcn is bounded by the volume's total cluster count, which ntfs3 holds in sbi->used.bitmap.nbits (set up in ntfs_init_from_boot() before any caller of mi_enum_attr() runs). Reject evcn values that fall outside this range.

However, an empty non-resident attribute (no allocated clusters) is legitimately encoded with svcn == 0 and evcn == -1 (U64_MAX), e.g. via attr->nres.evcn = cpu_to_le64((u64)vcn - 1) with vcn == 0. That sentinel must keep passing, so exclude evcn == U64_MAX from the range check. The existing "svcn > evcn + 1" test still tolerates the sentinel ("0 > 0" is false) and continues to require svcn == 0 for it, while the range check rejects every other out-of-range evcn and thereby also defuses the "evcn + 1" wraparound.

svcn does not need its own bound: once evcn < nbits, "svcn > evcn + 1" implies svcn <= nbits.

[almaz.alexandrovich@paragon-software.com: fixed evcn check]

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 013ff63b649475f0ee134e2c8d0c8e65284ede50 to 0441e34ce098c19185a7b52c5b8b89a8a5b26888 (excl.)
  • affected from 013ff63b649475f0ee134e2c8d0c8e65284ede50 to 7ab69cef49ebdfee288287d62641b24ab1445ecc (excl.)
  • affected from 013ff63b649475f0ee134e2c8d0c8e65284ede50 to ce9a619c432b9a4044fee115c5483fbed946c131 (excl.)
  • affected from 013ff63b649475f0ee134e2c8d0c8e65284ede50 to 2b9a0e57bfd365e2096706b19ae34dce3b4a884b (excl.)
  • affected from 013ff63b649475f0ee134e2c8d0c8e65284ede50 to 20fd9f64c0050658f2031e6bd5d552c6f0c8f7e3 (excl.)
  • Version a7accf181a4709a6e380360372150cc4a1b6b89a is affected
  • Version 3dfd727873c3e8da74a2e3907120ff052c5f0bcc is affected
  • Version 1d7dd485108d4f633b543c9c14071cc325b68ae5 is affected
  • affected from 5.15.209 to 5.16 (excl.)
  • affected from 6.1.115 to 6.2 (excl.)
  • affected from 6.5.11 to 6.6 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.6 is affected
  • unaffected from 0 to 6.6 (excl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References