Skip to main content
Vulnerability Database/CVE-2026-98140

CVE-2026-98140: Linux Kernel NTFS Information Disclosure

CVE-2026-98140 is an information disclosure vulnerability in the Linux kernel NTFS filesystem that causes memory mapping corruption through improper cleanup in error paths. This article covers technical details, affected versions, impact analysis, and mitigation strategies.

Published:

CVE-2026-98140 Overview

CVE-2026-98140 is a memory mapping leak in the Linux kernel's NTFS filesystem driver. The flaw resides in write_mft_record_nolock(), which maps a Master File Table (MFT) record folio using kmap_local_folio() but fails to unmap it on specific error paths. When pre_write_mst_fixup() or bio_add_folio() fail, control jumps to the error label without releasing the mapping.

Because kmap_local mappings are stack-ordered per task, leaking one entry corrupts the nesting for any outer mapping. This can destabilize subsequent kernel operations relying on temporary mappings.

Critical Impact

Leaked kmap_local mappings corrupt per-task mapping stack ordering, destabilizing any outer mapping and risking kernel memory consistency on NTFS write paths.

Affected Products

  • Linux kernel builds containing the NTFS driver prior to the fix commits
  • Stable kernel branches referenced by Git commits 5d7f7bf8 and cf06dcd5
  • Distributions shipping affected kernels with NTFS write support enabled

Discovery Timeline

  • 2026-09-25 - CVE-2026-98140 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-98140

Vulnerability Analysis

The Linux kernel's NTFS driver writes MFT records through write_mft_record_nolock(). The function obtains a temporary virtual mapping for the record folio with kmap_local_folio(). This mapping must be released with the matching unmap call before the function returns.

Two error branches skip the unmap step. If pre_write_mst_fixup() fails during multi-sector transfer protection fixups, execution jumps to the error label with the mapping still active. The same pattern occurs when bio_add_folio() fails to attach the folio to the block I/O request.

The kmap_local API maintains a strict last-in, first-out stack of mappings per task. Leaking one entry desynchronizes the stack, so any mapping taken by an outer caller unmaps the wrong slot. This corruption can propagate into unrelated filesystem or page cache operations.

Root Cause

The root cause is a missing cleanup call on specific failure branches [CWE-401 class: Missing Release of Resource]. The function allocates a stack-scoped mapping but does not pair every exit path with the corresponding unmap. The error label was written assuming the mapping had not yet been established.

Attack Vector

Triggering the leak requires reaching the specific error conditions inside pre_write_mst_fixup() or bio_add_folio() while writing MFT records on a mounted NTFS volume. This typically requires local filesystem activity. Impact is limited to kernel stability rather than direct code execution, but repeated triggering can cascade into broader memory handling faults.

See the fix commits for implementation details: Kernel Git Commit 5d7f7bf8 and Kernel Git Commit cf06dcd5.

Detection Methods for CVE-2026-98140

Indicators of Compromise

  • Kernel log warnings referencing kmap_local imbalance or stack corruption during NTFS write operations
  • Unexpected BUG or WARN messages originating from fs/ntfs/ write paths
  • Sporadic filesystem errors on NTFS volumes under write pressure

Detection Strategies

  • Inventory running kernel versions and compare against the patched stable commits 5d7f7bf8 and cf06dcd5
  • Enable CONFIG_DEBUG_KMAP_LOCAL and CONFIG_DEBUG_HIGHMEM in test builds to surface mapping imbalances
  • Correlate kernel oops events with NTFS write workloads in centralized logging

Monitoring Recommendations

  • Forward dmesg and /var/log/kern.log to a SIEM and alert on NTFS-related stack traces
  • Track mount events for NTFS volumes on servers where that filesystem is unexpected
  • Monitor kernel crash dumps for recurring faults inside write_mft_record_nolock

How to Mitigate CVE-2026-98140

Immediate Actions Required

  • Apply the upstream stable kernel patches referenced by commits 5d7f7bf8 and cf06dcd5
  • Rebuild or update distribution kernels to a release that includes both fix commits
  • Reboot affected systems after installing the patched kernel package

Patch Information

The fix adds the missing kunmap_local call on the pre_write_mst_fixup() and bio_add_folio() failure branches of write_mft_record_nolock(). The corrections are published in the mainline and stable trees as commit 5d7f7bf8 and commit cf06dcd5.

Workarounds

  • Mount NTFS volumes read-only where write access is not required
  • Unload the ntfs module on systems that do not require NTFS support
  • Restrict local user access to systems with writable NTFS volumes until patched
bash
# Verify running kernel and NTFS module status
uname -r
lsmod | grep ntfs

# Example: remount an NTFS volume read-only as a temporary mitigation
mount -o remount,ro /mnt/ntfs_volume

# Example: prevent the ntfs module from loading automatically
echo 'blacklist ntfs' | sudo tee /etc/modprobe.d/blacklist-ntfs.conf

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.