Skip to main content
EPSS 0.7%top 50%

Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() When… (CVE-2026-72185)

0
Medium
Published: 08/17/2026 (08/17/2026, 00:00:00 UTC)
Source: GCVE Database
Product: linux-hwe-edge

Description

In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() When ntfs_map_runlist_nolock() needs to look up the attribute extent containing a target VCN (ctx_needs_reset == true), it calls ntfs_attr_lookup() and then expects the result to be a non-resident attribute, since only non-resident attributes have a mapping pairs array to decompress. A crafted NTFS image can place a resident attribute where a non-resident one is expected, causing ntfs_attr_lookup() to succeed but return a resident attribute record. Previously this was caught only by a WARN_ON(), which does not stop execution. The code then falls through to read a->data.non_resident.highest_vcn from what is actually a resident attribute, accessing the wrong union member and corrupting the VCN range check. The caller path triggering this warning during mount is: ntfs_map_runlist_nolock ntfs_empty_logfile load_system_files ntfs_fill_super In this path ctx is NULL, so ntfs_map_runlist_nolock() allocates a temporary search context internally and sets ctx_needs_reset = true. The existing resident-attribute guard in the ctx != NULL branch already returns -EIO silently for the same condition; make the ctx_needs_reset path consistent by replacing the WARN_ON() with the same -EIO error return. This causes the crafted image to be rejected with a mount error instead of triggering a kernel warning.

CVSS v3.1

Score 9.8critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 16:50:53 UTC

Technical Analysis

The Linux kernel's NTFS driver function ntfs_map_runlist_nolock() expects to find a non-resident attribute when looking up attribute extents. A crafted NTFS image could place a resident attribute where a non-resident one was expected, causing ntfs_attr_lookup() to return a resident attribute record. Previously, this was caught only by a WARN_ON() which did not halt execution, leading to incorrect access of a union member and corruption of the VCN range check. The vulnerability was fixed by replacing the WARN_ON() with an error return (-EIO), causing the mount operation to fail safely when encountering such crafted images.

Potential Impact

The vulnerability could cause the kernel to access incorrect memory fields due to a resident attribute being treated as non-resident, potentially leading to corruption of the VCN range check during NTFS mount. This could result in kernel warnings and possibly unstable behavior during mount operations with crafted NTFS images. The fix prevents this by rejecting the malformed image with a mount error.

Mitigation Recommendations

A fix is available that replaces the WARN_ON() with an error return in the affected code path. Users should update to a Linux kernel version that includes this fix to ensure that crafted NTFS images causing this condition are rejected safely during mount. Patch status is not explicitly stated in the input data; check the vendor advisory for the exact fixed kernel versions and update accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-8g34-c4r8-pmf8
Osv Schema Version
1.4.0
Aliases
["CVE-2026-72185"]

Threat ID: 6a808b74bf8831d5394feb40

Added to database: 08/15/2026, 15:53:24 UTC

Last enriched: 08/15/2026, 16:50:53 UTC

Last updated: 09/30/2026, 09:47:10 UTC

Views: 31

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses