In the Linux kernel, the following vulnerability has been resolved: ntfs: fail attrlist updates when the superblock is inactive… (CVE-2026-72189)
A vulnerability in the Linux kernel's NTFS driver could cause a self-deadlock during inode eviction when the superblock is inactive. This occurs due to improper handling of a fake inode for the $ATTRIBUTE_LIST attribute, leading to a deadlock in the virtual file system layer. The issue has been resolved by preventing attribute-list inode lookups once the superblock is inactive, aborting updates instead of waiting on eviction.
AI Analysis
Technical Summary
The vulnerability involves the NTFS filesystem driver in the Linux kernel where, during superblock shutdown, the SB_ACTIVE flag is cleared before cached inodes are evicted. If the eviction process selects the fake inode representing the unnamed $ATTRIBUTE_LIST attribute of a base inode, the fake inode's reference on the base inode is dropped while it is still hashed and marked as I_FREEING. A subsequent iput call can synchronously write back the base inode, triggering a writeback path that calls ntfs_attrlist_update(), which unconditionally calls ntfs_attr_iget() for the same fake inode. Since the inode is marked I_FREEING, the virtual file system waits for eviction to finish, but the current task is already inside that eviction path, causing a self-deadlock in find_inode(). The fix mirrors the teardown guard used elsewhere, ensuring that once SB_ACTIVE is cleared, the attribute-list fake inode is not iget, and the update is aborted with an -EIO error instead of waiting on the inode being evicted.
Potential Impact
The vulnerability can cause a self-deadlock in the kernel's NTFS driver during inode eviction when the superblock is inactive. This could lead to kernel hangs or denial of service conditions due to the deadlock. There is no indication of code execution or privilege escalation from the provided data.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to prevent this deadlock by aborting attribute-list updates once the superblock is inactive. Since no patch links or vendor advisories are provided, patch status is not yet confirmed — check the official Linux kernel advisories or repositories for the current remediation guidance. Until patched, avoid operations that trigger superblock shutdown on NTFS filesystems if possible.
In the Linux kernel, the following vulnerability has been resolved: ntfs: fail attrlist updates when the superblock is inactive… (CVE-2026-72189)
Description
A vulnerability in the Linux kernel's NTFS driver could cause a self-deadlock during inode eviction when the superblock is inactive. This occurs due to improper handling of a fake inode for the $ATTRIBUTE_LIST attribute, leading to a deadlock in the virtual file system layer. The issue has been resolved by preventing attribute-list inode lookups once the superblock is inactive, aborting updates instead of waiting on eviction.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability involves the NTFS filesystem driver in the Linux kernel where, during superblock shutdown, the SB_ACTIVE flag is cleared before cached inodes are evicted. If the eviction process selects the fake inode representing the unnamed $ATTRIBUTE_LIST attribute of a base inode, the fake inode's reference on the base inode is dropped while it is still hashed and marked as I_FREEING. A subsequent iput call can synchronously write back the base inode, triggering a writeback path that calls ntfs_attrlist_update(), which unconditionally calls ntfs_attr_iget() for the same fake inode. Since the inode is marked I_FREEING, the virtual file system waits for eviction to finish, but the current task is already inside that eviction path, causing a self-deadlock in find_inode(). The fix mirrors the teardown guard used elsewhere, ensuring that once SB_ACTIVE is cleared, the attribute-list fake inode is not iget, and the update is aborted with an -EIO error instead of waiting on the inode being evicted.
Potential Impact
The vulnerability can cause a self-deadlock in the kernel's NTFS driver during inode eviction when the superblock is inactive. This could lead to kernel hangs or denial of service conditions due to the deadlock. There is no indication of code execution or privilege escalation from the provided data.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to prevent this deadlock by aborting attribute-list updates once the superblock is inactive. Since no patch links or vendor advisories are provided, patch status is not yet confirmed — check the official Linux kernel advisories or repositories for the current remediation guidance. Until patched, avoid operations that trigger superblock shutdown on NTFS filesystems if possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-h6g4-x7wq-fhjg
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-72189"]
Threat ID: 6a808b74bf8831d5394feb16
Added to database: 08/15/2026, 15:53:24 UTC
Last enriched: 08/15/2026, 16:50:06 UTC
Last updated: 09/30/2026, 06:54:40 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.