In the Linux kernel, the following vulnerability has been resolved: ntfs: fix mrec_lock ABBA deadlock in rename ntfs_file_fsync(), ntfs_dir_fsync()… (CVE-2026-72190)
A deadlock vulnerability in the Linux kernel's NTFS implementation was resolved. The issue involved an ABBA deadlock condition caused by inconsistent locking order of inode and directory mrec_locks during rename and fsync operations. This could cause the kernel to hang when renaming files or directories under certain conditions. The fix enforces a consistent locking order to prevent deadlocks.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel's NTFS driver (CVE-2026-72190) was due to an ABBA deadlock involving mrec_lock locks on inodes and directories. Functions ntfs_file_fsync(), ntfs_dir_fsync(), and __ntfs_write_inode() lock an inode's mrec_lock before its parent directory's mrec_lock. Meanwhile, ntfs_rename() locks the source inode and source directory before the target inode or target directory, which can cause a deadlock if fsync or write_inode holds the target inode or directory while rename waits on it. The fix changes the locking order to acquire the existing target inode lock before any parent directory locks, and for cross-directory renames, locks the target parent before the source parent to maintain a consistent child-to-parent locking order.
Potential Impact
This deadlock vulnerability could cause the Linux kernel to hang or become unresponsive during NTFS file or directory rename operations under specific conditions. It affects system stability but does not directly lead to code execution or privilege escalation. There are no known exploits in the wild.
Mitigation Recommendations
A fix for this deadlock issue has been implemented in the Linux kernel NTFS driver. Users should update to a kernel version that includes this fix once it is released. Since this is a kernel-level fix, applying the official kernel update is the recommended remediation. Patch status is not explicitly confirmed in the provided data; users should consult the vendor or kernel release notes for the exact fixed version.
In the Linux kernel, the following vulnerability has been resolved: ntfs: fix mrec_lock ABBA deadlock in rename ntfs_file_fsync(), ntfs_dir_fsync()… (CVE-2026-72190)
Description
A deadlock vulnerability in the Linux kernel's NTFS implementation was resolved. The issue involved an ABBA deadlock condition caused by inconsistent locking order of inode and directory mrec_locks during rename and fsync operations. This could cause the kernel to hang when renaming files or directories under certain conditions. The fix enforces a consistent locking order to prevent deadlocks.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel's NTFS driver (CVE-2026-72190) was due to an ABBA deadlock involving mrec_lock locks on inodes and directories. Functions ntfs_file_fsync(), ntfs_dir_fsync(), and __ntfs_write_inode() lock an inode's mrec_lock before its parent directory's mrec_lock. Meanwhile, ntfs_rename() locks the source inode and source directory before the target inode or target directory, which can cause a deadlock if fsync or write_inode holds the target inode or directory while rename waits on it. The fix changes the locking order to acquire the existing target inode lock before any parent directory locks, and for cross-directory renames, locks the target parent before the source parent to maintain a consistent child-to-parent locking order.
Potential Impact
This deadlock vulnerability could cause the Linux kernel to hang or become unresponsive during NTFS file or directory rename operations under specific conditions. It affects system stability but does not directly lead to code execution or privilege escalation. There are no known exploits in the wild.
Mitigation Recommendations
A fix for this deadlock issue has been implemented in the Linux kernel NTFS driver. Users should update to a kernel version that includes this fix once it is released. Since this is a kernel-level fix, applying the official kernel update is the recommended remediation. Patch status is not explicitly confirmed in the provided data; users should consult the vendor or kernel release notes for the exact fixed version.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-7xmj-mqhm-5492
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-72190"]
Threat ID: 6a808b74bf8831d5394feb45
Added to database: 08/15/2026, 15:53:24 UTC
Last enriched: 08/15/2026, 16:50:59 UTC
Last updated: 09/30/2026, 06:54:40 UTC
Views: 32
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.