PatchSiren cyber security CVE debrief
CVE-2026-72185 Linux CVE debrief
A crafted NTFS image can cause the Linux kernel to access the wrong union member, corrupting the VCN range check, due to a vulnerability in ntfs_map_runlist_nolock(). This vulnerability occurs when the function fails to properly handle resident attributes, allowing an attacker to potentially cause a mount error. Linux kernel developers and maintainers should review the patch and apply it to affected systems. The patch replaces the WARN_ON() with an -EIO error return in ntfs_map_runlist_nolock(), causing the crafted image to be rejected with a mount error instead of triggering a kernel warning. Evidence limits suggest that affected scope and impact are still being researched and verified.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux-based systems should be aware of this vulnerability and take steps to mitigate it. Affected product deployments should be identified and prioritized for patching. Security teams should monitor for potential exploitation and implement compensating controls where necessary.
Technical summary
The vulnerability occurs in the Linux kernel's ntfs_map_runlist_nolock() function, which can be exploited by a crafted NTFS image, potentially causing a mount error. The function fails to properly handle resident attributes, allowing an attacker to corrupt the VCN range check. To address this, Linux kernel developers and maintainers should review and apply the patch to affected systems. The patch implementation should be verified, and testing for exposure should be conducted. Additionally, security teams should monitor for potential exploitation and implement compensating controls where necessary.
Defensive priority
The vulnerability can cause a mount error, allowing attackers to potentially exploit the system.
Recommended defensive actions
- Review and apply the patch to the Linux kernel.
- Monitor for and block malicious NTFS images.
- Implement compensating controls, such as intrusion detection and prevention systems.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The vulnerability was resolved by replacing the WARN_ON() with an -EIO error return in ntfs_map_runlist_nolock(). This change causes the crafted image to be rejected with a mount error instead of triggering a kernel warning. Linux kernel developers should verify the patch implementation and test for exposure. Evidence limits suggest that affected scope and impact are still being researched and verified.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72185 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72185
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72185 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72185
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b397b1238a217264bb02f963a1a1eadf71906375
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b8d6c528e9d57d263fee1a648409f84a68b2561d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.