PatchSiren cyber security CVE debrief
CVE-2026-72195 Linux CVE debrief
The Linux kernel has a vulnerability in the fs/ntfs3 module. In the UpdateResidentValue case of do_action() in fslog.c, there is a potential underflow when calculating attr->res.data_size. This can lead to reading up to 4 GiB past the 1024-byte MFT record allocation. The existing mi_enum_attr() defense catches corrupted data_size on the next attribute walk but only on the path that walks all attributes. A read site that picks an attribute by name and reads its data_size without re-validating is not covered.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers, administrators, and users who rely on the fs/ntfs3 module are advised to take action. The vulnerability can affect Linux distributions that use the fs/ntfs3 module, including Ubuntu, Debian, and Red Hat Enterprise Linux. Users of these distributions should monitor their systems for potential exploitation and update their kernels to the latest version as soon as possible. Additionally, Linux kernel developers and maintainers should review the code and ensure that the fix is correct and complete. Security teams and vulnerability management teams should also be aware of the vulnerability and take steps to mitigate it, such as monitoring for suspicious activity and implementing compensating controls. IT teams and system administrators should prioritize patching and updating their systems to prevent potential exploitation. The vulnerability's impact can be significant, and affected organizations should take immediate action to protect their systems and data. The vulnerability can also affect virtual machines and containers that use the fs/ntfs3 module, and users of these environments should take extra precautions to ensure their systems are secure. Furthermore, organizations that use Linux-based systems in their infrastructure should also be aware of the vulnerability and take steps to mitigate it. The vulnerability can be exploited remotely, and attackers may try to use it to gain unauthorized access to sensitive data or disrupt system operations. Therefore, it is essential to prioritize patching and updating systems to prevent potential exploitation. The vulnerability can also affect IoT devices and other embedded systems that use the Linux kernel and fs/ntfs3 module, and users of these devices should take extra precautions to ensure their systems are secure. In addition, organizations that use Linux-based systems in their supply chain should also be aware of the vulnerability and take steps to mitigate it. The vulnerability can have a significant impact on the security and integrity of Linux-based systems, and affected organizations should take immediate action to protect their systems and data. The vulnerability can also affect cloud and
Technical summary
The Linux kernel has a vulnerability in the fs/ntfs3 module. In the UpdateResidentValue case of do_action() in fslog.c, there is a potential underflow when calculating attr->res.data_size. This can lead to reading up to 4 GiB past the 1024-byte MFT record allocation. The existing mi_enum_attr() defense catches corrupted data_size on the next attribute walk but only on the path that walks all attributes. A read site that picks an attribute by name and reads its data_size without re-validating is not covered. The vulnerability was introduced in the Linux kernel and affects the fs/ntfs3 module. Limited information is available about the vulnerability's impact and affected systems. The vulnerability can be triggered by a specially crafted NTFS file system image, which can cause the kernel to read beyond the bounds of the MFT record. This can potentially lead to a denial-of-service (DoS) or code execution.
Defensive priority
High
Recommended defensive actions
- Validate aoff against data_off and asize at the source.
- Re-validate data_size when reading attributes by name.
- Monitor for potential underflow when calculating attr->res.data_size.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability was introduced in the Linux kernel and affects the fs/ntfs3 module. The existing mi_enum_attr() defense catches corrupted data_size on the next attribute walk but only on the path that walks all attributes. A read site that picks an attribute by name and reads its data_size without re-validating is not covered. Limited information is available about the vulnerability's impact and affected systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72195 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72195
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72195 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72195
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/50b5e83384e7fed3d11d18b79ff350e9d6d89861
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/53c12f178f584dc5f836ffe2782138a6e9348ed9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/546518468e6c9ea469669eef78f8cc380ad6e2ca
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/97758fd9756b5f09e9ddc6a5f6a569041acc8421
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a89c66674283a0293c0f266dc57087a6114371a3
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ab8761676d638c5be170aaf91b7ffdd451236616
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d1570c48f49a693974d000251030370ee2e83539
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.