Vulnerability Details CVE-2026-98139
In the Linux kernel, the following vulnerability has been resolved:
ntfs: only count successfully cleared runs when freeing clusters
ntfs_cluster_free_from_rl_nolock() adds a run's length to nr_freed
whenever the error bookkeeping condition is false, which includes
cases where ntfs_bitmap_clear_run() actually failed - e.g. a second
run failing with the same errno as an earlier one, or any failure
after a non-ENOMEM error was already recorded. Since a failed
ntfs_bitmap_clear_run() rolls back its partial modifications, no
bits were cleared for that run, yet its length still inflates
vol->free_clusters, corrupting statfs output and the allocator's
free space gate.
Only count runs whose bitmap clear succeeded.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 6.6%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2026-98139
-
cpe:2.3:o:linux:linux_kernel:7.1.13
-
cpe:2.3:o:linux:linux_kernel:7.3