What is CVE-2026-64533?
This is a critical vulnerability in the fs/ntfs3 driver of the Linux kernel caused by insufficient validation of the 'lcns_follow' value in the log_replay() function, potentially leading to privilege escalation or system crash when handling malicious NTFS volumes. Users interacting with NTFS partitions should apply the necessary kernel updates.
Azərbaycanca: Bu Linux kernel daxilində fs/ntfs3 sürücüsündə aşkarlanmış kritik boşluqdur. log_replay() funksiyasındakı 'lcns_follow' dəyərinin yetərsiz yoxlanması səbəbindən yaranır və zərərli NTFS həcmləri ilə işləyərkən privilege escalation və ya sistemin çökməsinə səbəb ola bilər. NTFS bölmələri ilə işləyən istifadəçilər kernel yeniləməsini tətbiq etməlidir.
FAQ2
In which component of the Linux kernel was CVE-2026-64533 discovered and what is the root cause?
The vulnerability exists in the fs/ntfs3 driver, specifically caused by insufficient validation of the 'lcns_follow' value in the log_replay() function.
What potential consequences can CVE-2026-64533 cause when handling malicious NTFS volumes?
This vulnerability can potentially lead to privilege escalation or a system crash.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.