ZeroHour
Story · 1 source · 3 articlesfirst updated ()

ZDI Discloses Three Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerabilities

mediumVulnerabilityimportance 25
What's new: This is the first merged summary for this story. It consolidates the three newly published ZDI advisories (ZDI-26-697, ZDI-26-698, ZDI-26-699) covering out-of-bounds read flaws in the Linux Kernel NTFS3 driver; no prior coverage exists.
Merged summary · glm-5.3 · rewritten as coverage arrives

ZDI published three advisories on 2026-09-14 for out-of-bounds read flaws in the Linux Kernel NTFS3 driver — ZDI-26-697 (CVSS 7.3), ZDI-26-698 (CVSS 5.2), and ZDI-26-699 (CVSS 5.2) — all allowing local low-privileged attackers to disclose sensitive…

Three advisories from the Zero Day Initiative, all dated 2026-09-14, describe out-of-bounds read vulnerabilities in the Linux Kernel NTFS3 driver: ZDI-26-697 is rated CVSS 7.3, while ZDI-26-698 and ZDI-26-699 are each rated CVSS 5.2. In every case, exploitation requires the attacker to first obtain the ability to execute low-privileged code on the target system, and successful exploitation results in local disclosure of sensitive information — no other impact is described. None of the three advisories list a CVE identifier. The reports are consistent on all details except the CVSS scores, where ZDI-26-697 (7.3) is rated higher than the other two (5.2).

  • Three ZDI advisories dated 2026-09-14: ZDI-26-697, ZDI-26-698, and ZDI-26-699
  • All three flaws are out-of-bounds reads in the Linux Kernel NTFS3 driver
  • CVSS scores: ZDI-26-697 rated 7.3; ZDI-26-698 and ZDI-26-699 each rated 5.2
  • All three enable local information disclosure of sensitive information only
  • Exploitation of each flaw requires prior ability to execute low-privileged code on the target system
  • No CVE identifiers are listed in any of the three advisories

Coverage timeline

  1. · 1d ago
    ZDI Published Advisories· 15
    ZDI-26-699: Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerability

    ZDI-26-699: Linux Kernel NTFS3 out-of-bounds read (CVSS 5.2) lets local low-privileged attackers disclose sensitive information.

  2. · 1d ago
    ZDI Published Advisories· 25
    ZDI-26-697: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

    ZDI-26-697: Linux Kernel NTFS3 out-of-bounds read rated CVSS 7.3 lets local low-privileged attackers disclose sensitive information.

  3. · 1d ago
    ZDI Published Advisories· 15
    ZDI-26-698: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

    ZDI-26-698: Linux Kernel NTFS3 out-of-bounds read (CVSS 5.2) allows local attackers to disclose sensitive information on affected systems.