{"id":"AZL-93962","summary":"CVE-2026-64533 affecting package kernel for versions less than 6.6.145.2-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate lcns_follow in log_replay conversion\n\nlog_replay() converts DIR_PAGE_ENTRY_32 records into DIR_PAGE_ENTRY\nrecords when replaying version 0 restart tables.\n\nDuring this conversion, the memmove() length is derived directly from\nthe on-disk lcns_follow field:\n\n\tmemmove(&dp-\u003evcn, &dp0-\u003evcn_low,\n\t\t2 * sizeof(u64) +\n\t\t\t\tle32_to_cpu(dp-\u003elcns_follow) * sizeof(u64));\n\ncheck_rstbl() validates restart table structure, but does not constrain\nper-entry lcns_follow values relative to the entry size. A malformed\nfilesystem image can provide an oversized lcns_follow value, causing\nthe conversion memmove() to access memory beyond the bounds of the\nallocated restart table buffer.\n\nThe same field is later used to bound iteration over page_lcns[],\nso validating lcns_follow during conversion also prevents downstream\nout-of-bounds access from the same malformed metadata.\n\nCompute the maximum valid lcns_follow from the already-validated\nrestart table entry size and reject entries that exceed this bound.\nReuse the existing t16/t32 scratch variables already declared in\nlog_replay() to avoid introducing new declarations.\n\n[almaz.alexandrovich@paragon-software.com: fixed the conflicts]","modified":"2026-08-28T17:47:46.443337534Z","published":"2026-07-27T08:16:22Z","upstream":["CVE-2026-64533"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64533"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.6.145.2-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93962.json"}}],"schema_version":"1.9.0"}