PatchSiren cyber security CVE debrief
CVE-2026-72192 Linux CVE debrief
A crafted NTFS image can trigger a controlled out-of-bounds write of 120-136 bytes past a kmalloc(index_block_size) allocation with attacker-controlled content, reachable from unprivileged open(O_CREAT) on a mounted crafted NTFS image. This issue affects Linux systems that process NTFS images, particularly those with unprivileged user access. The vulnerability is a bounded adjacent-heap corruption primitive, not an arbitrary-address write. Successful exploitation into a named victim object depends on the surrounding slab layout.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux system administrators, security teams, and users of Linux systems that process NTFS images should be aware of this vulnerability. Those responsible for maintaining systems that handle NTFS filesystems, especially in environments where unprivileged user access is common, should prioritize patching or mitigating this issue. Additionally, security teams should monitor for suspicious activity related to NTFS image processing and implement compensating controls to detect and prevent exploitation. Linux distributions and vendors should also be aware of this issue and provide guidance and patches as necessary. Users of Linux systems that rely on NTFS filesystems should review their exposure and take steps to protect their systems until patches are available. This may involve implementing secure mounting options for NTFS filesystems and closely monitoring system logs for signs of exploitation attempts. Furthermore, Linux kernel developers and maintainers should review the ntfs3 subsystem to identify similar vulnerabilities and improve the overall security posture of the Linux kernel's filesystem handling. Security researchers and auditors may also want to review the vulnerability details to understand the attack surface and potential impact on Linux systems. Lastly, organizations that rely on Linux systems for critical infrastructure or sensitive data processing should consider prioritizing patching and mitigation efforts for this vulnerability due to its potential impact on system integrity and confidentiality. The vulnerability's impact is not limited to specific industries but affects any organization using Linux systems with NTFS filesystem support. Therefore, a broad awareness and response are necessary to address this vulnerability effectively across various sectors and use cases. Linux users and administrators should stay informed about updates and patches from their distribution vendors and apply them as soon as possible to minimize risk. In addition to patching, implementing general security best practices such as least privilege access, monitoring system logs, and using secure protocols can help mitigate the risk associated with this and similar vulnearb
Technical summary
The Linux kernel's ntfs3 subsystem has a vulnerability where a crafted NTFS image can cause a controlled out-of-bounds write of 120-136 bytes past a kmalloc(index_block_size) allocation with attacker-controlled content. This is reachable from unprivileged open(O_CREAT) on a mounted crafted NTFS image. The write is a bounded adjacent-heap corruption primitive, not an arbitrary-address write. Successful exploitation into a named victim object depends on the surrounding slab layout.
Defensive priority
Medium
Recommended defensive actions
- Inventory and assess Linux systems for exposure to crafted NTFS images
- Implement compensating controls to detect and prevent exploitation
- Monitor for suspicious activity related to NTFS image processing
- Apply vendor patches or updates when available
- Consider using secure mounting options for NTFS filesystems
Evidence notes
The Linux kernel's ntfs3 subsystem has a vulnerability where a crafted NTFS image can cause a controlled out-of-bounds write. The write is a bounded adjacent-heap corruption primitive, not an arbitrary-address write. Successful exploitation into a named victim object depends on the surrounding slab layout.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72192 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72192
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72192 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72192
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0af83b8155cc848e9f5d2c36e20a70d024214649
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/194b00c99ba971fa7cf6acd747a36032c6de54eb
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/53c5f3b2da3774b41534728aba295c098c9efa19
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9b6926ac9c970ae0b2c2fe6289b16e9aa10b6a67
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/aaa1f956c0fc41089a4a534da7df91552a08a47c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/cb3161deebcaf8d36d3115abf452c633f2180fc1
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d240f5f9d036b8180224954d9873f172b6be4dd8
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.