In the Linux kernel, the following vulnerability has been resolved: ntfs: propagate reparse...

zetlyn/cve-ghsa vulnerability ghsa GHSA-m767-h27w-j97x cve CVE-2026-98141 known 2026-09-25

https://github.com/advisories/GHSA-m767-h27w-j97x

Properties

severityunknown
receipt
Source
GitHub advisories
Its words
unknown
Read by
field:severity
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-98141",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [],
  "description": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: propagate reparse index insertion failure\n\nupdate_reparse_data() ignores the return value of\nset_reparse_index(). When index insertion fails, the code removes\nthe just-written reparse data as cleanup but still returns 0, so\nsymlink(2) (and WSL special file creation) reports success while\nno reparse data exists on disk. When there was no previous reparse\ndata (oldsize == 0), the failure was likewise silently ignored.\n\nPropagate the error to the caller.",
  "epss": {
    "percentage": 0.00145,
    "percentile": 0.03122
  },
  "ghsa_id": "GHSA-m767-h27w-j97x",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-m767-h27w-j97x",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-m767-h27w-j97x"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-98141"
    }
  ],
  "nvd_published_at": "2026-09-25T11:17:45Z",
  "published_at": "2026-09-25T12:31:38Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-98141",
    "https://git.kernel.org/stable/c/9692b1b4fc00cf89628bc43f71729ab21f14f8d3",
    "https://git.kernel.org/stable/c/c62f446c63398dc7151f413069bf617032cf7a71",
    "https://github.com/advisories/GHSA-m767-h27w-j97x"
  ],
  "repository_advisory_url": null,
  "severity": "unknown",
  "source_code_location": "",
  "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: propagate reparse...",
  "type": "unreviewed",
  "updated_at": "2026-09-25T12:31:49Z",
  "url": "https://api.github.com/advisories/GHSA-m767-h27w-j97x",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

In the Linux kernel, the following vulnerability has been resolved: ntfs: propagate reparse... In the Linux kernel, the following vulnerability has been resolved: ntfs: propagate reparse index insertion failure update_reparse_data() ignores the return value of set_reparse_index(). When index insertion fails, the code removes the just-written reparse data as cleanup but still returns 0, so symlink(2) (and WSL special file creation) reports success while no reparse data exists on disk. When there was no previous reparse data (oldsize == 0), the failure was likewise silently ignored. Propagate the error to the caller.