CVE-2026-72196
Last modified
CVE-2026-72196 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass In log_replay()'s analysis pass, after find_dp() returns a valid DIR_PAGE_ENTRY for the (target_attr, target_vcn) tuple, the copy_lcns block walks lrh->lcns_follow further entries: t16 = le16_to_cpu(lrh->lcns_follow); for (i = 0; i < t16; i++) { size_t j = (size_t)(le64_to_cpu(lrh->target_vcn) - le64_to_cpu(dp->vcn)); dp->page_lcns[j + i] = lrh->page_lcns[i]; } find_dp() only validates that target_vcn falls within [dp->vcn, dp->vcn + dp->lcns_follow), i.e., that the FIRST cluster is covered. The walk through the further entries is not bounded against dp->lcns_follow. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass In log_replay()'s analysis pass, after find_dp() returns a valid DIR_PAGE_ENTRY for the (target_attr, target_vcn) tuple, the copy_lcns block walks lrh->lcns_follow further entries: t16 = le16_to_cpu(lrh->lcns_follow); for (i = 0; i < t16; i++) { size_t j = (size_t)(le64_to_cpu(lrh->target_vcn) - le64_to_cpu(dp->vcn)); dp->page_lcns[j + i] = lrh->page_lcns[i]; } find_dp() only validates that target_vcn falls within [dp->vcn, dp->vcn + dp->lcns_follow), i.e., that the FIRST cluster is covered. The walk through the further entries is not bounded against dp->lcns_follow. For a malformed LRH where target_vcn = dp->vcn + dp->lcns_follow - 1 and lrh->lcns_follow > 1, the i > 0 writes overflow the dp's allocated page_lcns[] array. Add the missing j + lrh->lcns_follow <= dp->lcns_follow guard. Reproduced under UML+KASAN on mainline 8d90b09e6741 as a slab-out-of-bounds write of size 8 from log_replay+0x68d4 on the mount path. This is distinct from Pavitra Jha's 2026-05-02 patch ("fs/ntfs3: validate lcns_follow in log_replay conversion", <20260502154252.164586-1-jhapavitra98@gmail.com>) which addresses the separate version-0 dirty-page-table conversion path's memmove(&dp->vcn, ...) call. The two fixes are complementary; both should land. [almaz.alexandrovich@paragon-software.com: clang-formatted the changes, fixed conflicts]
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= b46acd6a6a627d876898e1c84d3f84902264b445, < 9b3d8cc9d54fcded4de51b2b1026ae7182512077; >= b46acd6a6a627d876898e1c84d3f84902264b445, < 9b7c28d8c61bdb041936222a09a708531a1c2921; >= b46acd6a6a627d876898e1c84d3f84902264b445, < 0f13e823bf86bd1800168ea0bb5bca8b8500a81c; >= b46acd6a6a627d876898e1c84d3f84902264b445, < d240cd98f5f7b65c90f6b2b6abe3232ccdc405ab; >= b46acd6a6a627d876898e1c84d3f84902264b445, < 49c86dae0c0ccb8d98ddcdc46987259389c816dd; >= b46acd6a6a627d876898e1c84d3f84902264b445, < 5e7b598660cfa8e5af172cf4c65cffc126333307 |
| Linux | Linux | 5.15 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-72196?
How severe is CVE-2026-72196?
How do I fix CVE-2026-72196?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72190In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72191In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-72192In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-72193In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72194In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-72195In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72197In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-72198In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72199In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-7220A vulnerability has been found in jackwrichards FastlyMCP up…7.3
- CVE-2026-72200In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-72201In the Linux kernel, the following vulnerability has been re…9.8
Are you affected by CVE-2026-72196?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
