Junglewise Threat Intelligence

CVE-2026-72184: Linux kernel NTFS memory leak in insert range error path

CVE-2026-72184 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NTFS file system driver contains a memory leak in the attribute insert range operation. When a runlist mapping operation fails during file attribute insertion, the code fails to free allocated memory, causing small amounts of memory to leak on each failed operation. Over time, this can lead to memory exhaustion on systems using NTFS partitions and performing insert range operations.

Technical details

This is a memory leak vulnerability in the NTFS driver's ntfs_non_resident_attr_insert_range() function. The function allocates memory for hole_rl before calling ntfs_attr_map_whole_runlist(). If the mapping call fails and returns an error, the code path releases a lock and returns without freeing the hole_rl allocation, leaking sizeof(*hole_rl) * 2 bytes per occurrence. The vulnerability requires file system operations that trigger attribute insert range on NTFS partitions, and affects any kernel version where the vulnerable code path exists. The fix is trivial: add a kfree(hole_rl) call before returning from the error path.

Affected products

  • Linux Linux kernel multiple versions (fix backported across stable branches)

Timeline

  • 2026-07-05: disclosed
  • 2026-07-06: patched

References

Related threats