PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72192 Linux CVE debrief

A crafted NTFS image can trigger a controlled out-of-bounds write of 120-136 bytes past a kmalloc(index_block_size) allocation with attacker-controlled content, reachable from unprivileged open(O_CREAT) on a mounted crafted NTFS image. This issue affects Linux systems that process NTFS images, particularly those with unprivileged user access. The vulnerability is a bounded adjacent-heap corruption primitive, not an arbitrary-address write. Successful exploitation into a named victim object depends on the surrounding slab layout.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux system administrators, security teams, and users of Linux systems that process NTFS images should be aware of this vulnerability. Those responsible for maintaining systems that handle NTFS filesystems, especially in environments where unprivileged user access is common, should prioritize patching or mitigating this issue. Additionally, security teams should monitor for suspicious activity related to NTFS image processing and implement compensating controls to detect and prevent exploitation. Linux distributions and vendors should also be aware of this issue and provide guidance and patches as necessary. Users of Linux systems that rely on NTFS filesystems should review their exposure and take steps to protect their systems until patches are available. This may involve implementing secure mounting options for NTFS filesystems and closely monitoring system logs for signs of exploitation attempts. Furthermore, Linux kernel developers and maintainers should review the ntfs3 subsystem to identify similar vulnerabilities and improve the overall security posture of the Linux kernel's filesystem handling. Security researchers and auditors may also want to review the vulnerability details to understand the attack surface and potential impact on Linux systems. Lastly, organizations that rely on Linux systems for critical infrastructure or sensitive data processing should consider prioritizing patching and mitigation efforts for this vulnerability due to its potential impact on system integrity and confidentiality. The vulnerability's impact is not limited to specific industries but affects any organization using Linux systems with NTFS filesystem support. Therefore, a broad awareness and response are necessary to address this vulnerability effectively across various sectors and use cases. Linux users and administrators should stay informed about updates and patches from their distribution vendors and apply them as soon as possible to minimize risk. In addition to patching, implementing general security best practices such as least privilege access, monitoring system logs, and using secure protocols can help mitigate the risk associated with this and similar vulnearb

Technical summary

The Linux kernel's ntfs3 subsystem has a vulnerability where a crafted NTFS image can cause a controlled out-of-bounds write of 120-136 bytes past a kmalloc(index_block_size) allocation with attacker-controlled content. This is reachable from unprivileged open(O_CREAT) on a mounted crafted NTFS image. The write is a bounded adjacent-heap corruption primitive, not an arbitrary-address write. Successful exploitation into a named victim object depends on the surrounding slab layout.

Defensive priority

Medium

Recommended defensive actions

  • Inventory and assess Linux systems for exposure to crafted NTFS images
  • Implement compensating controls to detect and prevent exploitation
  • Monitor for suspicious activity related to NTFS image processing
  • Apply vendor patches or updates when available
  • Consider using secure mounting options for NTFS filesystems

Evidence notes

The Linux kernel's ntfs3 subsystem has a vulnerability where a crafted NTFS image can cause a controlled out-of-bounds write. The write is a bounded adjacent-heap corruption primitive, not an arbitrary-address write. Successful exploitation into a named victim object depends on the surrounding slab layout.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72192 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72192

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72192 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72192

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0af83b8155cc848e9f5d2c36e20a70d024214649

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/194b00c99ba971fa7cf6acd747a36032c6de54eb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/53c5f3b2da3774b41534728aba295c098c9efa19

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9b6926ac9c970ae0b2c2fe6289b16e9aa10b6a67

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/aaa1f956c0fc41089a4a534da7df91552a08a47c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/cb3161deebcaf8d36d3115abf452c633f2180fc1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d240f5f9d036b8180224954d9873f172b6be4dd8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.