PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72194 Linux CVE debrief

A stack overflow vulnerability exists in the Linux kernel's ntfs3 filesystem implementation. The `indx_find_buffer` function recursively descends a B+ tree index without a depth limit, allowing a crafted NTFS image with circular index node references to cause a stack overflow and panic the system. This can be triggered by mounting a malicious NTFS filesystem and deleting a file whose index entry triggers the rebalancing fallback path. The vulnerability has a high impact on system availability and can be exploited by a local attacker with low privileges. The affected product is the Linux kernel, and the vulnerability is related to the ntfs3 filesystem implementation.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux system administrators, security teams, and users of ntfs3 filesystems should be aware of this vulnerability and take steps to mitigate it. They should assess their exposure to ntfs3 filesystems, implement compensating controls, and monitor for suspicious activity related to ntfs3 filesystems. Additionally, they should apply patches or updates to the Linux kernel as they become available. The vulnerability has a high impact on system availability, and exploitation can cause a system panic, making it essential for Linux system administrators and security teams to prioritize mitigation efforts.

Technical summary

The Linux kernel's ntfs3 filesystem implementation is vulnerable to a stack overflow attack due to the lack of a depth limit in the `indx_find_buffer` function. A crafted NTFS image with circular index node references can cause a stack overflow and panic the system. This can be triggered by mounting a malicious NTFS filesystem and deleting a specific file. The vulnerability is caused by the recursive descent of the B+ tree index without a depth limit, which allows an attacker to cause a stack overflow. The affected product is the Linux kernel, and the vulnerability is related to the ntfs3 filesystem implementation.

Defensive priority

High

Recommended defensive actions

  • Inventory and assess Linux systems for exposure to ntfs3 filesystems
  • Implement compensating controls, such as restricting access to ntfs3 filesystems
  • Monitor for suspicious activity related to ntfs3 filesystems
  • Apply patches or updates to the Linux kernel as they become available
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. The Linux kernel's ntfs3 filesystem implementation is vulnerable to a stack overflow attack. The `indx_find_buffer` function lacks a depth limit, allowing a crafted NTFS image to cause a stack overflow. The vulnerability can be triggered by mounting a malicious NTFS filesystem and deleting a specific file.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72194 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72194

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72194 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72194

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1ebd684b8f627f75bc3e03f8b2ad8400fd1f02cd

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/65357a81f64cb3fbe13b4b937586755e4b3a072f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/78612f478f9fadcec4f9b3b089970da67ffb47e9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/908c9243ba309997b73cbda3e4c563d0fb345ee9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/96fb64f9da86fd2dbd78fbe9d9e41ae27e12ce34

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/99031d4f63c785d2a985b6a4c64c4256f7117052

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/fdf50c788e0991e42a187ff75479a0df7fb752f1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.