Skip to main content
EPSS 0.2%top 91%

In the Linux kernel, the following vulnerability has been resolved: ntfs: fail attrlist updates when the superblock is inactive… (CVE-2026-72189)

0
Medium
Published: 08/15/2026 (08/15/2026, 06:32:15 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's NTFS driver could cause a self-deadlock during inode eviction when the superblock is inactive. This occurs due to improper handling of a fake inode for the $ATTRIBUTE_LIST attribute, leading to a deadlock in the virtual file system layer. The issue has been resolved by preventing attribute-list inode lookups once the superblock is inactive, aborting updates instead of waiting on eviction.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 16:50:06 UTC

Technical Analysis

The vulnerability involves the NTFS filesystem driver in the Linux kernel where, during superblock shutdown, the SB_ACTIVE flag is cleared before cached inodes are evicted. If the eviction process selects the fake inode representing the unnamed $ATTRIBUTE_LIST attribute of a base inode, the fake inode's reference on the base inode is dropped while it is still hashed and marked as I_FREEING. A subsequent iput call can synchronously write back the base inode, triggering a writeback path that calls ntfs_attrlist_update(), which unconditionally calls ntfs_attr_iget() for the same fake inode. Since the inode is marked I_FREEING, the virtual file system waits for eviction to finish, but the current task is already inside that eviction path, causing a self-deadlock in find_inode(). The fix mirrors the teardown guard used elsewhere, ensuring that once SB_ACTIVE is cleared, the attribute-list fake inode is not iget, and the update is aborted with an -EIO error instead of waiting on the inode being evicted.

Potential Impact

The vulnerability can cause a self-deadlock in the kernel's NTFS driver during inode eviction when the superblock is inactive. This could lead to kernel hangs or denial of service conditions due to the deadlock. There is no indication of code execution or privilege escalation from the provided data.

Mitigation Recommendations

A fix has been implemented in the Linux kernel to prevent this deadlock by aborting attribute-list updates once the superblock is inactive. Since no patch links or vendor advisories are provided, patch status is not yet confirmed — check the official Linux kernel advisories or repositories for the current remediation guidance. Until patched, avoid operations that trigger superblock shutdown on NTFS filesystems if possible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-h6g4-x7wq-fhjg
Osv Schema Version
1.4.0
Aliases
["CVE-2026-72189"]

Threat ID: 6a808b74bf8831d5394feb16

Added to database: 08/15/2026, 15:53:24 UTC

Last enriched: 08/15/2026, 16:50:06 UTC

Last updated: 09/30/2026, 06:54:40 UTC

Views: 60

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses