CVE-2026-31716Disclosure(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate rec->used in journal-replay file record check check_file_record() validates rec->total against the record size but never validates rec->used. The do_action() journal-replay handlers read rec->used from disk and use it to compute memmove lengths: DeleteAttribute: memmove(attr, ..., used - asize - roff) CreateAttribute: memmove(..., attr, used - roff) change_attr_size: memmove(..., used - PtrOffset(rec, next)) When rec->used is smaller than the offset of a validated attribute, or larger than the record size, these subtractions can underflow allowing us to copy huge amounts of memory in to a 4kb buffer, generally considered a bad idea overall. This requires a corrupted filesystem, which isn't a threat model the kernel really needs to worry about, but checking for such an obvious out-of-bounds value is good to keep things robust, especially on journal replay Fix this up by bounding rec->used correctly. This is much like commit b2bc7c44ed17 ("fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot") which checked different values in this same switch statement.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-01); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-01: 1Mentions · 2026-05-23: 1Patch / Workaround · 2026-05-23: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-23: 105-0105-23
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-011
Disclosure1
2026-05-231
Patch1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31716 Buffer Overflow in Linux Kernel NTFS3 Journal-Replay File Record Validation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31716

    Post summary

    A newly reported CVE‑2026‑31716 describes a buffer overflow in the Linux kernel’s NTFS3 journal‑replay file record validation, but no proof‑of‑concept, exploit, patch, or active exploitation details are provided.

    0000164
    4.0K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-31716 (CVSS 7.8) Linux kernel NTFS3 vulnerability allows out-of-bounds memory copy during journal replay. Affects fs/ntfs3 subsystem. Impact: Local code execution via corrupted filesystem Patch available. #CVE #Vulnerability #PatchNow https://t.co/L33WwfRxMQ

    Post summary

    CVE-2026-31716 is an out‑of‑bounds memory copy bug in the Linux kernel NTFS3 subsystem, allowing local code execution with a CVSS 7.8 score. A patch is available and no PoC or active exploitation is reported.

    0000059
    30 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.1--

Explore more