Bug 2541369 (CVE-2026-98137) - CVE-2026-98137 kernel: ntfs: treat any nonzero dio zero-range return as an error
Summary: CVE-2026-98137 kernel: ntfs: treat any nonzero dio zero-range return as an error
Keywords:
Status: NEW
Alias: CVE-2026-98137
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 11:36 UTC by OSIDB Bzimport
Modified: 2026-09-28 15:17 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 11:36:11 UTC
In the Linux kernel, the following vulnerability has been resolved:

ntfs: treat any nonzero dio zero-range return as an error

ntfs_dio_zero_range() returns either 0 or a negative errno from
blkdev_issue_zeroout(); it never returns a positive value.  The
zeroing failure check in ntfs_attr_fallocate() therefore never fired,
so a failed zeroing operation was silently ignored: the loop kept
going, the newly allocated clusters were folded into initialized_size
and the write could succeed leaving stale on-disk data.

Treat any nonzero return as an error and abort the allocation.


Note You need to log in before you can comment on or make changes to this bug.