Skip to content
ThreatCluster

Multiple Vulnerabilities in Linux Kernel NTFS3 Disclosed

First seen 14 Sep 2026, 17:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 18:57 UTC
  • Four vulnerabilities in Linux Kernel NTFS3 disclosed on September 14, 2026.
  • Exploitation requires local low-privileged code execution.
  • Linux has released patches to mitigate these vulnerabilities.

Four vulnerabilities affecting the Linux Kernel's NTFS3 file system have been disclosed, allowing local attackers to disclose sensitive information or execute arbitrary code. The vulnerabilities require low-privileged code execution for exploitation. The flaws include issues with directory index entries, directory headers, extended attributes, and NTFS3 journal log records, all stemming from improper validation of user-supplied data. The vulnerabilities can lead to reading past allocated arrays or writing past allocated buffers, potentially enabling attackers to escalate privileges. Linux has issued updates to address these vulnerabilities. The advisories were publicly released on September 14, 2026, following a report to the vendor on June 10, 2026. Security professionals are urged to apply the patches promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-10
Vulnerabilities reported to vendor
Multiple vulnerabilities in Linux Kernel NTFS3 were reported to the Linux development team.
Article 1
2026-09-14
Coordinated public release of advisories
Advisories for vulnerabilities ZDI-26-696, ZDI-26-697, ZDI-26-698, and ZDI-26-699 were released.
Article 1
2026-09-14
Advisories updated
The advisories were updated with additional details regarding the vulnerabilities.
Article 1

More articles in this cluster (5)