Linux Kernel

severity

7.5

published

A flaw in the Linux kernel's NTFS3 LZNT decompression path can expose uninitialized kernel page contents when reading a crafted compressed file. Bynario demonstrated that the disclosure can recover kernel pointers and determine the randomized kernel base, defeating KASLR and providing information useful for follow-on exploitation.

ni_read_frame() decompresses an LZNT $DATA frame into vmapped target pages and trusts the byte count returned by decompress_lznt(). When the compressed stream ends early, the decompressor may write substantially less than frame_size, leaving the tail between unc_size and frame_size untouched. If the frame lies within the file's valid-data range, the later zeroing logic does not cover that gap; the pages are nevertheless marked up to date and returned to userspace.

In Bynario's validation with KASLR enabled, a crafted file disclosed 3,341,928 nonzero bytes from a 4,193,792-byte read and exposed enough kernel pointers to recover the kernel base. The patch explicitly clears [unc_size, frame_size) after successful partial decompression. Bynario classifies the issue as CWE-908.

References

CVSS v3.1

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v3.1

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v3.1

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

SPt#aKr0tS  lBoCo&kPi3nEgP  aLt3  yZo#uQrY  s#oWfBt4w2a1rXeZ  cLr3i9t&i8c2a3l3lTyF.D

request briefing

request briefing

S@tBa8r9tQ  lWoIo@kMi#nSg%  a4tB  yJo@uMrO  sXoWfWtMw%a3rGeM  cKr0iRt9iBcNa4lYl6y0.8

request briefing

request briefing

SZtXa9r&tK  lIo6o$kUiCnZgA  aRtB  y6oPuIrQ  sToSfAtYwOa&rKe7  c9r0i@t6i%c3aUlClHyD.E

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026