- Sources: Phoronix report
- Summary: Phoronix reported on 2026-08-22 that Vova Tokarev disclosed the flaw publicly on the NTFS3 mailing list after reporting it privately two months earlier with no fix, and that it was still unaddressed in the mainline NTFS3 driver at the time of writing. An NTFS image carrying
$LXUID=0, $LXGID=0, and $LXMOD=0104755 in the MFT produces a setuid-root binary as soon as the volume is mounted, with no setxattr() call involved. Tokarev places the root cause at fs/ntfs3/xattr.c:1022, where inode->i_mode is assigned from untrusted on-disk data, proposes masking off S_ISUID and S_ISGID, states he holds a full proof of concept, and states udisks mounts NTFS with suid by default on desktops, so a crafted USB stick gives any local user euid 0. No CVE id is stated, and the flaw does not appear to affect the newer in-tree NTFS driver. The affected kernel versions are not yet known, because the source scopes the flaw to the mainline ntfs3 driver without naming a version range. - Why it matters: There is no patch, the precondition is only a local user on a desktop that automounts removable media, and the controls available today are mounting removable media
nosuid or not loading the ntfs3 driver. - Follow-up: Track a maintainer response, a CVE assignment, and the patch that lands the
S_ISUID and S_ISGID mask.
send feedback on this story