PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72193 Linux CVE debrief

A crafted NTFS3 disk image can trigger an in-kernel infinite loop at mount time, hanging the mounting thread and firing the soft-lockup watchdog. The bug is reachable from desktop USB auto-mount on distributions where udisks2 routes the NTFS signature to the in-tree ntfs3 driver. The issue is caused by an unbounded free-chain walker in the ntfs3 driver. A patched version of the driver bounds the walker by rt->used, preventing the infinite loop.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux systems that support NTFS3 disk images should be aware of this vulnerability. They should review the patch and apply it to affected systems to prevent exploitation. Additionally, they should monitor for suspicious activity related to NTFS3 disk images and consider implementing compensating controls, such as restricting access to NTFS3 disk images. Security teams should review the vulnerability and assess the risk to their organization. They should also ensure that their systems are updated with the patched driver and monitor for potential attacks. IT teams should prioritize patching affected systems and consider implementing additional security controls to prevent exploitation. Asset owners should inventory and assess Linux kernel installations for potential exposure and prioritize patching affected systems. Vulnerability management teams should review the vulnerability and assess the risk to their organization. They should also ensure that their systems are updated with the patched driver and monitor for potential attacks. Compensating controls, such as restricting access to NTFS3 disk images, should be considered while remediation is scheduled and verified. Monitoring and detection capabilities should be reviewed to ensure that they can detect potential attacks. Exceptions should be tracked, and remediated assets should be retested to ensure that the patch has been applied successfully. The patch should be applied through normal change control processes, and affected scope, severity, and vendor guidance should be validated. The vulnerability should be reviewed in the context of the organization's overall risk management strategy. The patched driver should be verified to ensure that it is functioning correctly. Rollback and change windows should be planned and implemented as necessary to minimize disruption to operations. Source tracking and monitoring should be implemented to detect potential attacks. Asset inventory and exposure review should be performed to identify potential vulnerabilities. Compensating controls, such as restricting access to NTFS3 disk images, shouldbe

Technical summary

The ntfs3 driver in the Linux kernel has an unbounded free-chain walker that can be triggered by a crafted NTFS3 disk image, leading to an in-kernel infinite loop at mount time. The issue is caused by a lack of bounds checking in the check_rstbl() function. A patched version of the driver bounds the walker by rt->used, preventing the infinite loop. The vulnerability is reachable from desktop USB auto-mount on distributions where udisks2 routes the NTFS signature to the in-tree ntfs3 driver. Linux kernel developers and maintainers should review the patch and apply it to affected systems.

Defensive priority

High

Recommended defensive actions

  • Inventory and assess Linux kernel installations for potential exposure.
  • Apply patches or updates to the ntfs3 driver to prevent exploitation.
  • Monitor for suspicious activity related to NTFS3 disk images.
  • Consider implementing compensating controls, such as restricting access to NTFS3 disk images.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further analysis of the Linux kernel source code and ntfs3 driver is required to fully understand the issue. The vulnerability is caused by an unbounded free-chain walker in the ntfs3 driver, which can be triggered by a crafted NTFS3 disk image. This can lead to an in-kernel infinite loop at mount time, hanging the mounting thread and firing the soft-lockup watchdog. The issue is reachable from desktop USB auto-mount on distributions where udisks2 routes the NTFS signature to the in-tree ntfs3 driver. A patched version of the driver bounds the walker by rt->used, preventing the infinite loop. Linux kernel developers and maintainers should review the patch and apply it to affected systems. Users of Linux systems that support NTFS3 disk images should ensure that their systems are updated with the patched driver.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72193 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72193

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72193 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72193

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0fad25687d4d3fa1fdd313d31b9cb5817c425029

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/29b86dbe88cbbef53bb9aaec2e279359f8c450f8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7972df425687daa70d971fe6ed415e78683133dd

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7ac4c86915c24c208a0f0611b71d9676686fe756

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8128bec895075253c779d67afdc90ae513265fca

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9611f644302c07d21bc8af97e3e06a3d30064253

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d313416280d41bea272f02a6034dfa88008692a0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.