MEDIUM

CVE-2026-53023

Linux Linux Kernel 2026-06-24 CVSS v3.1
CVSS
5.5

Description

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: terminate the cached volume label after UTF-8 conversion

ntfs_fill_super() loads the on-disk volume label with utf16s_to_utf8s()
and stores the result in sbi->volume.label. The converted label is later
exposed through ntfs3_label_show() using %s, but utf16s_to_utf8s() only
returns the number of bytes written and does not add a trailing NUL.

If the converted label fills the entire fixed buffer,
ntfs3_label_show() can read past the end of sbi->volume.label while
looking for a terminator.

Terminate the cached label explicitly after a successful conversion and
clamp the exact-full case to the last byte of the buffer.

Summary dbcve.org

In the NTFS3 Linux kernel driver, utf16s_to_utf8s() converts the on-disk volume label from UTF-16 to UTF-8 but does not add a trailing NUL terminator. When the converted label exactly fills the fixed buffer, ntfs3_label_show() using %s format specifier reads past the buffer end while searching for a NUL, causing an out-of-bounds read vulnerability.

Mitigation

Apply the kernel patch that explicitly terminates the converted label with NUL after utf16s_to_utf8s() and clamps the full-buffer case. Update to a kernel version containing this fix.

Patch Commit

EPSS Score

0.12%
Probability of exploitation in next 30 days
2.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE