What is CVE-2026-64532?
In the Linux kernel's NTFS3 file system driver, a vulnerability was discovered due to improper boundary checking in the `UpdateRecordDataRoot` and `UpdateRecordDataAllocation` functions when performing a `memmove` operation. This could lead to memory corruption via local exploitation. Users of the NTFS3 driver should apply security updates.
Azərbaycanca: Linux kernel-in NTFS3 fayl sistemi sürücüsündə `UpdateRecordDataRoot` və `UpdateRecordDataAllocation` funksiyalarında `memmove` əməliyyatı zamanı buffer sərhədlərinin düzgün yoxlanılmaması aşkar edilib. Bu, yerli istismar yolu ilə yaddaş korrupsiyasına səbəb ola bilər. NTFS3 drayverindən istifadə edən istifadəçilərin təhlükəsizlik yeniləmələrini tətbiq etməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
Which Linux kernel component does CVE-2026-64532 affect?
The NTFS3 file system driver.
During what operation does this vulnerability occur?
During a `memmove` operation in the `UpdateRecordDataRoot` and `UpdateRecordDataAllocation` functions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.