CVE-2026-98140 Overview
CVE-2026-98140 is a memory mapping leak in the Linux kernel's NTFS filesystem driver. The flaw resides in write_mft_record_nolock(), which maps a Master File Table (MFT) record folio using kmap_local_folio() but fails to unmap it on specific error paths. When pre_write_mst_fixup() or bio_add_folio() fail, control jumps to the error label without releasing the mapping.
Because kmap_local mappings are stack-ordered per task, leaking one entry corrupts the nesting for any outer mapping. This can destabilize subsequent kernel operations relying on temporary mappings.
Critical Impact
Leaked kmap_local mappings corrupt per-task mapping stack ordering, destabilizing any outer mapping and risking kernel memory consistency on NTFS write paths.
Affected Products
- Linux kernel builds containing the NTFS driver prior to the fix commits
- Stable kernel branches referenced by Git commits 5d7f7bf8 and cf06dcd5
- Distributions shipping affected kernels with NTFS write support enabled
Discovery Timeline
- 2026-09-25 - CVE-2026-98140 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-98140
Vulnerability Analysis
The Linux kernel's NTFS driver writes MFT records through write_mft_record_nolock(). The function obtains a temporary virtual mapping for the record folio with kmap_local_folio(). This mapping must be released with the matching unmap call before the function returns.
Two error branches skip the unmap step. If pre_write_mst_fixup() fails during multi-sector transfer protection fixups, execution jumps to the error label with the mapping still active. The same pattern occurs when bio_add_folio() fails to attach the folio to the block I/O request.
The kmap_local API maintains a strict last-in, first-out stack of mappings per task. Leaking one entry desynchronizes the stack, so any mapping taken by an outer caller unmaps the wrong slot. This corruption can propagate into unrelated filesystem or page cache operations.
Root Cause
The root cause is a missing cleanup call on specific failure branches [CWE-401 class: Missing Release of Resource]. The function allocates a stack-scoped mapping but does not pair every exit path with the corresponding unmap. The error label was written assuming the mapping had not yet been established.
Attack Vector
Triggering the leak requires reaching the specific error conditions inside pre_write_mst_fixup() or bio_add_folio() while writing MFT records on a mounted NTFS volume. This typically requires local filesystem activity. Impact is limited to kernel stability rather than direct code execution, but repeated triggering can cascade into broader memory handling faults.
See the fix commits for implementation details: Kernel Git Commit 5d7f7bf8 and Kernel Git Commit cf06dcd5.
Detection Methods for CVE-2026-98140
Indicators of Compromise
- Kernel log warnings referencing kmap_local imbalance or stack corruption during NTFS write operations
- Unexpected BUG or WARN messages originating from fs/ntfs/ write paths
- Sporadic filesystem errors on NTFS volumes under write pressure
Detection Strategies
- Inventory running kernel versions and compare against the patched stable commits 5d7f7bf8 and cf06dcd5
- Enable CONFIG_DEBUG_KMAP_LOCAL and CONFIG_DEBUG_HIGHMEM in test builds to surface mapping imbalances
- Correlate kernel oops events with NTFS write workloads in centralized logging
Monitoring Recommendations
- Forward dmesg and /var/log/kern.log to a SIEM and alert on NTFS-related stack traces
- Track mount events for NTFS volumes on servers where that filesystem is unexpected
- Monitor kernel crash dumps for recurring faults inside write_mft_record_nolock
How to Mitigate CVE-2026-98140
Immediate Actions Required
- Apply the upstream stable kernel patches referenced by commits 5d7f7bf8 and cf06dcd5
- Rebuild or update distribution kernels to a release that includes both fix commits
- Reboot affected systems after installing the patched kernel package
Patch Information
The fix adds the missing kunmap_local call on the pre_write_mst_fixup() and bio_add_folio() failure branches of write_mft_record_nolock(). The corrections are published in the mainline and stable trees as commit 5d7f7bf8 and commit cf06dcd5.
Workarounds
- Mount NTFS volumes read-only where write access is not required
- Unload the ntfs module on systems that do not require NTFS support
- Restrict local user access to systems with writable NTFS volumes until patched
# Verify running kernel and NTFS module status
uname -r
lsmod | grep ntfs
# Example: remount an NTFS volume read-only as a temporary mitigation
mount -o remount,ro /mnt/ntfs_volume
# Example: prevent the ntfs module from loading automatically
echo 'blacklist ntfs' | sudo tee /etc/modprobe.d/blacklist-ntfs.conf
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.