PatchSiren cyber security CVE debrief
CVE-2026-72191 Linux CVE debrief
A crafted NTFS image can cause an out-of-bounds kernel write in the Linux kernel's ntfs3 module, leading to a kernel panic. The vulnerability is due to a lack of validation in the hdr_find_split function, which can return a split point that extends past the end of the buffer. This issue arises when the function fails to properly validate the split-point offset, allowing an attacker to create a specially crafted NTFS image that triggers the vulnerability. The vulnerability affects Linux kernel versions prior to the patched version and requires local access to the system, where an attacker with low privileges can exploit it. The impact on the system's confidentiality, integrity, and availability is high. To mitigate this vulnerability, users should apply the patch from the Linux kernel stable repository, restrict access to the vulnerable system, and monitor system logs for suspicious activity.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-23
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-23
Who should care
Linux kernel developers, Linux distribution maintainers, and users of Linux systems that use the ntfs3 module. The vulnerability affects Linux kernel versions prior to the patched version. The vulnerability has a high impact on the system's confidentiality, integrity, and availability. The vulnerability requires local access to the system and can be exploited by a low-privileged user.
Technical summary
The vulnerability is due to a lack of validation in the hdr_find_split function, which can return a split point that extends past the end of the buffer. This can cause an out-of-bounds kernel write, leading to a kernel panic. The vulnerability affects the Linux kernel's ntfs3 module. The vulnerability can be exploited by a local attacker with low privileges. The vulnerability has a high impact on the system's confidentiality, integrity, and availability.
Defensive priority
High
Recommended defensive actions
- Apply the patch from the Linux kernel stable repository
- Restrict access to the vulnerable system
- Monitor system logs for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability was discovered in the Linux kernel's ntfs3 module. A crafted NTFS image can cause an out-of-bounds kernel write, leading to a kernel panic. The vulnerability is due to a lack of validation in the hdr_find_split function. The vulnerability was reported by an unknown researcher and patched by a Linux kernel developer. The patch was applied to the Linux kernel stable repository. The vulnerability affects Linux kernel versions prior to the patched version. The vulnerability has a high impact on the system's confidentiality, integrity, and availability. The vulnerability requires local access to the system and can be exploited by a low-privileged user. The vulnerability can be mitigated by restricting access to the vulnerable system, monitoring system logs for suspicious activity, and applying the patch from the Linux kernel stable repository.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72191 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72191
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72191 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72191
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1758a564b6ebe7f4a82f23c9851d1cae15549457
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7bf74e6baf810fe325f111996496c678fc6e244f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b232eb5c9fe11ec2368e9b565db69c724c35fbd2
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/f1df9d771df47aa40de6d70949c28720ae1e430d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/f3624cc069195001c88df7a291af215f2133ff2c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.