CVE-2026-72477
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: call ntfsbad_inode() when failing to rename
It is safe to call ntfsbad_inode on live inodes since:
commit 519b078998ce ("fs/ntfs3: Exclude call makebadinode for live nodes.")
The WARN_ON was added when it wasn't safe by:
commit d99208b91933 ("fs/ntfs3: cancle set bad inode after removing name fails")
Replace the WARNON with a call to ntfsbadinode() to prevent further
operations on the inconsistent inode.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/e8ed78f40eecd0176fda71d673f6957c98e7ffbe, https://git.kernel.org/stable/c/ff825bf0521f6da2f30878cbad18ab7b341bc31b, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72477.json, https://nvd.nist.gov/vuln/detail/CVE-2026-72477, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git