Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() When… (CVE-2026-72185)
In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() When ntfs_map_runlist_nolock() needs to look up the attribute extent containing a target VCN (ctx_needs_reset == true), it calls ntfs_attr_lookup() and then expects the result to be a non-resident attribute, since only non-resident attributes have a mapping pairs array to decompress. A crafted NTFS image can place a resident attribute where a non-resident one is expected, causing ntfs_attr_lookup() to succeed but return a resident attribute record. Previously this was caught only by a WARN_ON(), which does not stop execution. The code then falls through to read a->data.non_resident.highest_vcn from what is actually a resident attribute, accessing the wrong union member and corrupting the VCN range check. The caller path triggering this warning during mount is: ntfs_map_runlist_nolock ntfs_empty_logfile load_system_files ntfs_fill_super In this path ctx is NULL, so ntfs_map_runlist_nolock() allocates a temporary search context internally and sets ctx_needs_reset = true. The existing resident-attribute guard in the ctx != NULL branch already returns -EIO silently for the same condition; make the ctx_needs_reset path consistent by replacing the WARN_ON() with the same -EIO error return. This causes the crafted image to be rejected with a mount error instead of triggering a kernel warning.
AI Analysis
Technical Summary
The Linux kernel's NTFS driver function ntfs_map_runlist_nolock() expects to find a non-resident attribute when looking up attribute extents. A crafted NTFS image could place a resident attribute where a non-resident one was expected, causing ntfs_attr_lookup() to return a resident attribute record. Previously, this was caught only by a WARN_ON() which did not halt execution, leading to incorrect access of a union member and corruption of the VCN range check. The vulnerability was fixed by replacing the WARN_ON() with an error return (-EIO), causing the mount operation to fail safely when encountering such crafted images.
Potential Impact
The vulnerability could cause the kernel to access incorrect memory fields due to a resident attribute being treated as non-resident, potentially leading to corruption of the VCN range check during NTFS mount. This could result in kernel warnings and possibly unstable behavior during mount operations with crafted NTFS images. The fix prevents this by rejecting the malformed image with a mount error.
Mitigation Recommendations
A fix is available that replaces the WARN_ON() with an error return in the affected code path. Users should update to a Linux kernel version that includes this fix to ensure that crafted NTFS images causing this condition are rejected safely during mount. Patch status is not explicitly stated in the input data; check the vendor advisory for the exact fixed kernel versions and update accordingly.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() When… (CVE-2026-72185)
Description
In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() When ntfs_map_runlist_nolock() needs to look up the attribute extent containing a target VCN (ctx_needs_reset == true), it calls ntfs_attr_lookup() and then expects the result to be a non-resident attribute, since only non-resident attributes have a mapping pairs array to decompress. A crafted NTFS image can place a resident attribute where a non-resident one is expected, causing ntfs_attr_lookup() to succeed but return a resident attribute record. Previously this was caught only by a WARN_ON(), which does not stop execution. The code then falls through to read a->data.non_resident.highest_vcn from what is actually a resident attribute, accessing the wrong union member and corrupting the VCN range check. The caller path triggering this warning during mount is: ntfs_map_runlist_nolock ntfs_empty_logfile load_system_files ntfs_fill_super In this path ctx is NULL, so ntfs_map_runlist_nolock() allocates a temporary search context internally and sets ctx_needs_reset = true. The existing resident-attribute guard in the ctx != NULL branch already returns -EIO silently for the same condition; make the ctx_needs_reset path consistent by replacing the WARN_ON() with the same -EIO error return. This causes the crafted image to be rejected with a mount error instead of triggering a kernel warning.
CVSS v3.1
Score 9.8critical
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's NTFS driver function ntfs_map_runlist_nolock() expects to find a non-resident attribute when looking up attribute extents. A crafted NTFS image could place a resident attribute where a non-resident one was expected, causing ntfs_attr_lookup() to return a resident attribute record. Previously, this was caught only by a WARN_ON() which did not halt execution, leading to incorrect access of a union member and corruption of the VCN range check. The vulnerability was fixed by replacing the WARN_ON() with an error return (-EIO), causing the mount operation to fail safely when encountering such crafted images.
Potential Impact
The vulnerability could cause the kernel to access incorrect memory fields due to a resident attribute being treated as non-resident, potentially leading to corruption of the VCN range check during NTFS mount. This could result in kernel warnings and possibly unstable behavior during mount operations with crafted NTFS images. The fix prevents this by rejecting the malformed image with a mount error.
Mitigation Recommendations
A fix is available that replaces the WARN_ON() with an error return in the affected code path. Users should update to a Linux kernel version that includes this fix to ensure that crafted NTFS images causing this condition are rejected safely during mount. Patch status is not explicitly stated in the input data; check the vendor advisory for the exact fixed kernel versions and update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8g34-c4r8-pmf8
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-72185"]
Threat ID: 6a808b74bf8831d5394feb40
Added to database: 08/15/2026, 15:53:24 UTC
Last enriched: 08/15/2026, 16:50:53 UTC
Last updated: 09/30/2026, 09:47:10 UTC
Views: 31
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.