PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72195 Linux CVE debrief

The Linux kernel has a vulnerability in the fs/ntfs3 module. In the UpdateResidentValue case of do_action() in fslog.c, there is a potential underflow when calculating attr->res.data_size. This can lead to reading up to 4 GiB past the 1024-byte MFT record allocation. The existing mi_enum_attr() defense catches corrupted data_size on the next attribute walk but only on the path that walks all attributes. A read site that picks an attribute by name and reads its data_size without re-validating is not covered.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers, administrators, and users who rely on the fs/ntfs3 module are advised to take action. The vulnerability can affect Linux distributions that use the fs/ntfs3 module, including Ubuntu, Debian, and Red Hat Enterprise Linux. Users of these distributions should monitor their systems for potential exploitation and update their kernels to the latest version as soon as possible. Additionally, Linux kernel developers and maintainers should review the code and ensure that the fix is correct and complete. Security teams and vulnerability management teams should also be aware of the vulnerability and take steps to mitigate it, such as monitoring for suspicious activity and implementing compensating controls. IT teams and system administrators should prioritize patching and updating their systems to prevent potential exploitation. The vulnerability's impact can be significant, and affected organizations should take immediate action to protect their systems and data. The vulnerability can also affect virtual machines and containers that use the fs/ntfs3 module, and users of these environments should take extra precautions to ensure their systems are secure. Furthermore, organizations that use Linux-based systems in their infrastructure should also be aware of the vulnerability and take steps to mitigate it. The vulnerability can be exploited remotely, and attackers may try to use it to gain unauthorized access to sensitive data or disrupt system operations. Therefore, it is essential to prioritize patching and updating systems to prevent potential exploitation. The vulnerability can also affect IoT devices and other embedded systems that use the Linux kernel and fs/ntfs3 module, and users of these devices should take extra precautions to ensure their systems are secure. In addition, organizations that use Linux-based systems in their supply chain should also be aware of the vulnerability and take steps to mitigate it. The vulnerability can have a significant impact on the security and integrity of Linux-based systems, and affected organizations should take immediate action to protect their systems and data. The vulnerability can also affect cloud and

Technical summary

The Linux kernel has a vulnerability in the fs/ntfs3 module. In the UpdateResidentValue case of do_action() in fslog.c, there is a potential underflow when calculating attr->res.data_size. This can lead to reading up to 4 GiB past the 1024-byte MFT record allocation. The existing mi_enum_attr() defense catches corrupted data_size on the next attribute walk but only on the path that walks all attributes. A read site that picks an attribute by name and reads its data_size without re-validating is not covered. The vulnerability was introduced in the Linux kernel and affects the fs/ntfs3 module. Limited information is available about the vulnerability's impact and affected systems. The vulnerability can be triggered by a specially crafted NTFS file system image, which can cause the kernel to read beyond the bounds of the MFT record. This can potentially lead to a denial-of-service (DoS) or code execution.

Defensive priority

High

Recommended defensive actions

  • Validate aoff against data_off and asize at the source.
  • Re-validate data_size when reading attributes by name.
  • Monitor for potential underflow when calculating attr->res.data_size.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability was introduced in the Linux kernel and affects the fs/ntfs3 module. The existing mi_enum_attr() defense catches corrupted data_size on the next attribute walk but only on the path that walks all attributes. A read site that picks an attribute by name and reads its data_size without re-validating is not covered. Limited information is available about the vulnerability's impact and affected systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72195 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72195

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72195 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72195

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/50b5e83384e7fed3d11d18b79ff350e9d6d89861

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/53c12f178f584dc5f836ffe2782138a6e9348ed9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/546518468e6c9ea469669eef78f8cc380ad6e2ca

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/97758fd9756b5f09e9ddc6a5f6a569041acc8421

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a89c66674283a0293c0f266dc57087a6114371a3

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ab8761676d638c5be170aaf91b7ffdd451236616

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d1570c48f49a693974d000251030370ee2e83539

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.