PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72191 Linux CVE debrief

A crafted NTFS image can cause an out-of-bounds kernel write in the Linux kernel's ntfs3 module, leading to a kernel panic. The vulnerability is due to a lack of validation in the hdr_find_split function, which can return a split point that extends past the end of the buffer. This issue arises when the function fails to properly validate the split-point offset, allowing an attacker to create a specially crafted NTFS image that triggers the vulnerability. The vulnerability affects Linux kernel versions prior to the patched version and requires local access to the system, where an attacker with low privileges can exploit it. The impact on the system's confidentiality, integrity, and availability is high. To mitigate this vulnerability, users should apply the patch from the Linux kernel stable repository, restrict access to the vulnerable system, and monitor system logs for suspicious activity.

Vendor
Linux
Product
Unknown
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-23
Advisory published
2026-08-15
Advisory updated
2026-08-23

Who should care

Linux kernel developers, Linux distribution maintainers, and users of Linux systems that use the ntfs3 module. The vulnerability affects Linux kernel versions prior to the patched version. The vulnerability has a high impact on the system's confidentiality, integrity, and availability. The vulnerability requires local access to the system and can be exploited by a low-privileged user.

Technical summary

The vulnerability is due to a lack of validation in the hdr_find_split function, which can return a split point that extends past the end of the buffer. This can cause an out-of-bounds kernel write, leading to a kernel panic. The vulnerability affects the Linux kernel's ntfs3 module. The vulnerability can be exploited by a local attacker with low privileges. The vulnerability has a high impact on the system's confidentiality, integrity, and availability.

Defensive priority

High

Recommended defensive actions

  • Apply the patch from the Linux kernel stable repository
  • Restrict access to the vulnerable system
  • Monitor system logs for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability was discovered in the Linux kernel's ntfs3 module. A crafted NTFS image can cause an out-of-bounds kernel write, leading to a kernel panic. The vulnerability is due to a lack of validation in the hdr_find_split function. The vulnerability was reported by an unknown researcher and patched by a Linux kernel developer. The patch was applied to the Linux kernel stable repository. The vulnerability affects Linux kernel versions prior to the patched version. The vulnerability has a high impact on the system's confidentiality, integrity, and availability. The vulnerability requires local access to the system and can be exploited by a low-privileged user. The vulnerability can be mitigated by restricting access to the vulnerable system, monitoring system logs for suspicious activity, and applying the patch from the Linux kernel stable repository.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72191 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72191

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72191 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72191

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1758a564b6ebe7f4a82f23c9851d1cae15549457

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7bf74e6baf810fe325f111996496c678fc6e244f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b232eb5c9fe11ec2368e9b565db69c724c35fbd2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f1df9d771df47aa40de6d70949c28720ae1e430d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f3624cc069195001c88df7a291af215f2133ff2c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.