PatchSiren cyber security CVE debrief
CVE-2026-72193 Linux CVE debrief
A crafted NTFS3 disk image can trigger an in-kernel infinite loop at mount time, hanging the mounting thread and firing the soft-lockup watchdog. The bug is reachable from desktop USB auto-mount on distributions where udisks2 routes the NTFS signature to the in-tree ntfs3 driver. The issue is caused by an unbounded free-chain walker in the ntfs3 driver. A patched version of the driver bounds the walker by rt->used, preventing the infinite loop.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux systems that support NTFS3 disk images should be aware of this vulnerability. They should review the patch and apply it to affected systems to prevent exploitation. Additionally, they should monitor for suspicious activity related to NTFS3 disk images and consider implementing compensating controls, such as restricting access to NTFS3 disk images. Security teams should review the vulnerability and assess the risk to their organization. They should also ensure that their systems are updated with the patched driver and monitor for potential attacks. IT teams should prioritize patching affected systems and consider implementing additional security controls to prevent exploitation. Asset owners should inventory and assess Linux kernel installations for potential exposure and prioritize patching affected systems. Vulnerability management teams should review the vulnerability and assess the risk to their organization. They should also ensure that their systems are updated with the patched driver and monitor for potential attacks. Compensating controls, such as restricting access to NTFS3 disk images, should be considered while remediation is scheduled and verified. Monitoring and detection capabilities should be reviewed to ensure that they can detect potential attacks. Exceptions should be tracked, and remediated assets should be retested to ensure that the patch has been applied successfully. The patch should be applied through normal change control processes, and affected scope, severity, and vendor guidance should be validated. The vulnerability should be reviewed in the context of the organization's overall risk management strategy. The patched driver should be verified to ensure that it is functioning correctly. Rollback and change windows should be planned and implemented as necessary to minimize disruption to operations. Source tracking and monitoring should be implemented to detect potential attacks. Asset inventory and exposure review should be performed to identify potential vulnerabilities. Compensating controls, such as restricting access to NTFS3 disk images, shouldbe
Technical summary
The ntfs3 driver in the Linux kernel has an unbounded free-chain walker that can be triggered by a crafted NTFS3 disk image, leading to an in-kernel infinite loop at mount time. The issue is caused by a lack of bounds checking in the check_rstbl() function. A patched version of the driver bounds the walker by rt->used, preventing the infinite loop. The vulnerability is reachable from desktop USB auto-mount on distributions where udisks2 routes the NTFS signature to the in-tree ntfs3 driver. Linux kernel developers and maintainers should review the patch and apply it to affected systems.
Defensive priority
High
Recommended defensive actions
- Inventory and assess Linux kernel installations for potential exposure.
- Apply patches or updates to the ntfs3 driver to prevent exploitation.
- Monitor for suspicious activity related to NTFS3 disk images.
- Consider implementing compensating controls, such as restricting access to NTFS3 disk images.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further analysis of the Linux kernel source code and ntfs3 driver is required to fully understand the issue. The vulnerability is caused by an unbounded free-chain walker in the ntfs3 driver, which can be triggered by a crafted NTFS3 disk image. This can lead to an in-kernel infinite loop at mount time, hanging the mounting thread and firing the soft-lockup watchdog. The issue is reachable from desktop USB auto-mount on distributions where udisks2 routes the NTFS signature to the in-tree ntfs3 driver. A patched version of the driver bounds the walker by rt->used, preventing the infinite loop. Linux kernel developers and maintainers should review the patch and apply it to affected systems. Users of Linux systems that support NTFS3 disk images should ensure that their systems are updated with the patched driver.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72193 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72193
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72193 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72193
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0fad25687d4d3fa1fdd313d31b9cb5817c425029
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/29b86dbe88cbbef53bb9aaec2e279359f8c450f8
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7972df425687daa70d971fe6ed415e78683133dd
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7ac4c86915c24c208a0f0611b71d9676686fe756
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8128bec895075253c779d67afdc90ae513265fca
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9611f644302c07d21bc8af97e3e06a3d30064253
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d313416280d41bea272f02a6034dfa88008692a0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.