CVE-2026-90133
A CWE-122: Heap buffer overflow in the Linux kernel's NTFS filesystem driver can corrupt kernel memory. It occurs because ntfs_ir_to_ib() copies NTFS index entries into a fixed-size buffer without confirming they fit.
An attacker able to supply a crafted NTFS filesystem image can cause a heap out-of-bounds write after the image is processed by the Linux kernel. Successful exploitation could corrupt kernel memory, potentially causing a system crash or enabling arbitrary code execution in kernel context.
September 17, 2026
This issue affects the Linux kernel 7.1
CVE-2026-90133
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8
Update to Linux kernel 7.2.6
Alexandro Calo' at Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more