CVE-2023-26544: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux kernel 6.0.8, there is a use-after-free in run_unpack in fs/ntfs3/run.c, related to a difference between NTFS sector size and media sector size.
Affected products
- Linux Linux Kernel: from 5.15, before 5.15.87 (fixed in 5.15.87); from 5.16, before 6.0.17 (fixed in 6.0.17); from 6.1, before 6.1.3 (fixed in 6.1.3)
Published 2023-02-25. Last modified 2026-06-17.