PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72192 Linux CVE debrief

A crafted NTFS image can trigger a controlled out-of-bounds write of 120-136 bytes past a kmalloc(index_block_size) allocation with attacker-controlled content, reachable from unprivileged open(O_CREAT) on a mounted crafted NTFS image. This issue affects Linux systems that process NTFS images, particularly those with unprivileged user access. The vulnerability is a bounded adjacent-heap corruption primitive, not an arbitrary-address write. Successful exploitation into a named victim object depends on the surrounding slab layout.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux system administrators, security teams, and users of Linux systems that process NTFS images should be aware of this vulnerability. Those responsible for maintaining systems that handle NTFS filesystems, especially in environments where unprivileged user access is common, should prioritize patching or mitigating this issue. Additionally, security teams should monitor for suspicious activity related to NTFS image processing and implement compensating controls to detect and prevent exploitation. Linux distributions and vendors should also be aware of this issue and provide guidance and patches as necessary. Users of Linux systems that rely on NTFS filesystems should review their exposure and take steps to protect their systems until patches are available. This may involve implementing secure mounting options for NTFS filesystems and closely monitoring system logs for signs of exploitation attempts. Furthermore, Linux kernel developers and maintainers should review the ntfs3 subsystem to identify similar vulnerabilities and improve the overall security posture of the Linux kernel's filesystem handling. Security researchers and auditors may also want to review the vulnerability details to understand the attack surface and potential impact on Linux systems. Lastly, organizations that rely on Linux systems for critical infrastructure or sensitive data processing should consider prioritizing patching and mitigation efforts for this vulnerability due to its potential impact on system integrity and confidentiality. The vulnerability's impact is not limited to specific industries but affects any organization using Linux systems with NTFS filesystem support. Therefore, a broad awareness and response are necessary to address this vulnerability effectively across various sectors and use cases. Linux users and administrators should stay informed about updates and patches from their distribution vendors and apply them as soon as possible to minimize risk. In addition to patching, implementing general security best practices such as least privilege access, monitoring system logs, and using secure protocols can help mitigate the risk associated with this and similar vulnearb

Technical summary

The Linux kernel's ntfs3 subsystem has a vulnerability where a crafted NTFS image can cause a controlled out-of-bounds write of 120-136 bytes past a kmalloc(index_block_size) allocation with attacker-controlled content. This is reachable from unprivileged open(O_CREAT) on a mounted crafted NTFS image. The write is a bounded adjacent-heap corruption primitive, not an arbitrary-address write. Successful exploitation into a named victim object depends on the surrounding slab layout.

Defensive priority

Medium

Recommended defensive actions

  • Inventory and assess Linux systems for exposure to crafted NTFS images
  • Implement compensating controls to detect and prevent exploitation
  • Monitor for suspicious activity related to NTFS image processing
  • Apply vendor patches or updates when available
  • Consider using secure mounting options for NTFS filesystems

Evidence notes

The Linux kernel's ntfs3 subsystem has a vulnerability where a crafted NTFS image can cause a controlled out-of-bounds write. The write is a bounded adjacent-heap corruption primitive, not an arbitrary-address write. Successful exploitation into a named victim object depends on the surrounding slab layout.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T06:21:37.663Z and has not been modified since then.