Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-72185

In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() When ntfs_map_runlist_nolock() needs to look up the attribut...
Back to all
CVE

DEBIAN-CVE-2026-72185

In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() When ntfs_map_runlist_nolock() needs to look up the attribut...

In the Linux kernel, the following vulnerability has been resolved:  ntfs: fix WARNON for resident attribute in ntfsmaprunlistnolock()  When ntfsmaprunlistnolock() needs to look up the attribute extent containing a target VCN (ctxneedsreset == true), it calls ntfsattrlookup() and then expects the result to be a non-resident attribute, since only non-resident attributes have a mapping pairs array to decompress.  A crafted NTFS image can place a resident attribute where a non-resident one is expected, causing ntfsattrlookup() to succeed but return a resident attribute record.  Previously this was caught only by a WARNON(), which does not stop execution.  The code then falls through to read a->data.nonresident.highestvcn from what is actually a resident attribute, accessing the wrong union member and corrupting the VCN range check.  The caller path triggering this warning during mount is:    ntfsmaprunlistnolock   ntfsemptylogfile   loadsystemfiles   ntfsfillsuper  In this path ctx is NULL, so ntfsmaprunlistnolock() allocates a temporary search context internally and sets ctxneedsreset = true. The existing resident-attribute guard in the ctx != NULL branch already returns -EIO silently for the same condition; make the ctxneedsreset path consistent by replacing the WARN_ON() with the same -EIO error return.  This causes the crafted image to be rejected with a mount error instead of triggering a kernel warning.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-72185

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
7.1.5-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading