PatchSiren cyber security CVE debrief
CVE-2026-72194 Linux CVE debrief
A stack overflow vulnerability exists in the Linux kernel's ntfs3 filesystem implementation. The `indx_find_buffer` function recursively descends a B+ tree index without a depth limit, allowing a crafted NTFS image with circular index node references to cause a stack overflow and panic the system. This can be triggered by mounting a malicious NTFS filesystem and deleting a file whose index entry triggers the rebalancing fallback path. The vulnerability has a high impact on system availability and can be exploited by a local attacker with low privileges. The affected product is the Linux kernel, and the vulnerability is related to the ntfs3 filesystem implementation.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux system administrators, security teams, and users of ntfs3 filesystems should be aware of this vulnerability and take steps to mitigate it. They should assess their exposure to ntfs3 filesystems, implement compensating controls, and monitor for suspicious activity related to ntfs3 filesystems. Additionally, they should apply patches or updates to the Linux kernel as they become available. The vulnerability has a high impact on system availability, and exploitation can cause a system panic, making it essential for Linux system administrators and security teams to prioritize mitigation efforts.
Technical summary
The Linux kernel's ntfs3 filesystem implementation is vulnerable to a stack overflow attack due to the lack of a depth limit in the `indx_find_buffer` function. A crafted NTFS image with circular index node references can cause a stack overflow and panic the system. This can be triggered by mounting a malicious NTFS filesystem and deleting a specific file. The vulnerability is caused by the recursive descent of the B+ tree index without a depth limit, which allows an attacker to cause a stack overflow. The affected product is the Linux kernel, and the vulnerability is related to the ntfs3 filesystem implementation.
Defensive priority
High
Recommended defensive actions
- Inventory and assess Linux systems for exposure to ntfs3 filesystems
- Implement compensating controls, such as restricting access to ntfs3 filesystems
- Monitor for suspicious activity related to ntfs3 filesystems
- Apply patches or updates to the Linux kernel as they become available
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. The Linux kernel's ntfs3 filesystem implementation is vulnerable to a stack overflow attack. The `indx_find_buffer` function lacks a depth limit, allowing a crafted NTFS image to cause a stack overflow. The vulnerability can be triggered by mounting a malicious NTFS filesystem and deleting a specific file.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72194 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72194
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72194 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72194
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1ebd684b8f627f75bc3e03f8b2ad8400fd1f02cd
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/65357a81f64cb3fbe13b4b937586755e4b3a072f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/78612f478f9fadcec4f9b3b089970da67ffb47e9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/908c9243ba309997b73cbda3e4c563d0fb345ee9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/96fb64f9da86fd2dbd78fbe9d9e41ae27e12ce34
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/99031d4f63c785d2a985b6a4c64c4256f7117052
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/fdf50c788e0991e42a187ff75479a0df7fb752f1
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.