PatchSiren cyber security CVE debrief
CVE-2026-72189 Linux CVE debrief
The Linux kernel vulnerability CVE-2026-72189 is related to the handling of NTFS attribute list updates. When the superblock is inactive, updates to the attribute list can cause a self-deadlock in the find_inode() function. This issue arises because the eviction of cached inodes can lead to the writeback of the base inode, which in turn attempts to update the attribute list. To address this, a teardown guard has been added to prevent iget() from being called for the attribute-list fake inode once SB_ACTIVE has been cleared. The vulnerability affects Linux kernel administrators and users who rely on NTFS file systems. They should be aware of this vulnerability and take steps to mitigate it. The vulnerability has been resolved by mirroring the teardown guard used by __ntfs_write_inode().
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel administrators and users who rely on NTFS file systems should be aware of this vulnerability and take steps to mitigate it. This includes verifying and applying available Linux kernel updates, monitoring system logs for potential self-deadlock issues, and considering implementing compensating controls to mitigate the vulnerability. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated to ensure effective mitigation. Linux kernel administrators should verify and apply available updates to prevent potential self-deadlock issues. They should also review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets that need extra review should be checked. Exceptions, retest remediated assets, and close the item only after evidence is documented. Asset inventory and source tracking are crucial in this process. Rollback/change windows should be planned and implemented if necessary. Exposure review and vendor patch guidance are essential in mitigating this vulnerability. Monitoring and compensating controls can help reduce the risk associated with this vulnerability. It is essential to track exceptions and retest remediated assets to ensure that the mitigation measures are effective. The affected scope and severity of the vulnerability should be carefully evaluated to ensure that the mitigation measures are adequate. The vulnerability-management team should be involved in the mitigation process to ensure that the necessary measures are taken to mitigate the vulnerability. The security team should also be involved in the mitigation process to ensure that the necessary security measures are taken to mitigate the vulnerability. The operator and platform impact of the vulnerability should be carefully evaluated to ensure that the mitigation measures are adequate. The vulnerability-management and security teams should work together to ensure that the necessary measures are taken to mitigate the vulner
Technical summary
The Linux kernel vulnerability CVE-2026-72189 is related to the handling of NTFS attribute list updates. When the superblock is inactive, updates to the attribute list can cause a self-deadlock in the find_inode() function. This issue arises because the eviction of cached inodes can lead to the writeback of the base inode, which in turn attempts to update the attribute list. To address this, a teardown guard has been added to prevent iget() from being called for the attribute-list fake inode once SB_ACTIVE has been cleared.
Defensive priority
Linux kernel administrators should verify and apply available updates to prevent potential self-deadlock issues.
Recommended defensive actions
- Verify and apply available Linux kernel updates
- Monitor system logs for potential self-deadlock issues
- Consider implementing compensating controls to mitigate the vulnerability
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is related to the Linux kernel's handling of NTFS attribute list updates. When the superblock is inactive, updates to the attribute list can cause a self-deadlock in the find_inode() function. This issue arises because the eviction of cached inodes can lead to the writeback of the base inode, which in turn attempts to update the attribute list. To address this, a teardown guard has been added to prevent iget() from being called for the attribute-list fake inode once SB_ACTIVE has been cleared.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72189 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72189
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72189 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72189
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0ebe8f625ab0520217a425d7cd366e4670484941
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d5379035355c0dcb1e92a2544d40f48441e1d637
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.