Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-72185

ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock()
Back to all
CVE

CVE-2026-72185

ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock()

In the Linux kernel, the following vulnerability has been resolved:

ntfs: fix WARNON for resident attribute in ntfsmaprunlistnolock()

When ntfsmaprunlist_nolock() needs to look up the attribute extent

containing a target VCN (ctxneedsreset == true), it calls

ntfsattrlookup() and then expects the result to be a non-resident

attribute, since only non-resident attributes have a mapping pairs

array to decompress.

A crafted NTFS image can place a resident attribute where a non-resident

one is expected, causing ntfsattrlookup() to succeed but return a

resident attribute record.  Previously this was caught only by a

WARN_ON(), which does not stop execution.  The code then falls through to

read a->data.nonresident.highestvcn from what is actually a resident

attribute, accessing the wrong union member and corrupting the VCN range

check.

The caller path triggering this warning during mount is:

  ntfsmaprunlist_nolock

  ntfsemptylogfile

  loadsystemfiles

  ntfsfillsuper

In this path ctx is NULL, so ntfsmaprunlist_nolock() allocates a

temporary search context internally and sets ctxneedsreset = true.

The existing resident-attribute guard in the ctx != NULL branch already

returns -EIO silently for the same condition; make the ctxneedsreset

path consistent by replacing the WARN_ON() with the same -EIO error

return.

This causes the crafted image to be rejected with a mount error instead

of triggering a kernel warning.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/b397b1238a217264bb02f963a1a1eadf71906375, https://git.kernel.org/stable/c/b8d6c528e9d57d263fee1a648409f84a68b2561d, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72185.json, https://nvd.nist.gov/vuln/detail/CVE-2026-72185, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00626%
EPSS Percentile
0.47396%
Introduced Version
495e90fa334828d4119061e2726af51d0a0fb4ed,7.1.0,0
Fix Available
b8d6c528e9d57d263fee1a648409f84a68b2561d,7.1.5

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading