Executive brief
A vulnerability was identified in the Linux kernel's NTFS file system driver that could lead to a system crash. The issue occurs when the system attempts to read and change a disk's volume label at the exact same time. This could be exploited by a local user to cause a denial-of-service condition, potentially disrupting operations on systems using NTFS-formatted drives.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel NTFS driver (fs/ntfs) due to a race condition between FS_IOC_SETFSLABEL and FS_IOC_GETFSLABEL. When one process replaces the vol->volume_label via an ioctl call while another process concurrently reads it, the reading process may attempt to access memory that has already been freed. This occurs because the volume label access was not protected by a mutex. The fix introduces a volume_label_lock mutex to serialize these accesses and snapshots the label before copying it to user space. This is a local vulnerability requiring the ability to execute ioctl calls on an NTFS mount.
Affected products
- Linux Linux Kernel versions before 7.1.3, 7.2-rc1
Timeline
- 2026-06-02: other: Patch authored
- 2026-07-19: disclosed: CVE published
- 2026-07-19: patched: Fixes merged into stable branches