Executive brief
The Linux kernel's NTFS filesystem implementation contains a deadlock vulnerability during inode eviction. When writing files to disk, the filesystem can trigger inode cleanup that waits for the same write operation to complete, causing the system to hang. This can lead to service disruption on systems using NTFS volumes.
Technical details
The vulnerability is a self-deadlock in the NTFS filesystem code triggered during inode eviction. The root cause occurs in the ntfs_writepages() function: during an attribute-list update in cluster allocation, the temporary attribute inode is evicted, which drops a reference to the base inode and invokes ntfs_drop_big_inode(). If the base inode is unlinked, ntfs_drop_big_inode() calls truncate_setsize(), which waits for folio writeback completion. However, the same writeback worker thread is responsible for completing that writeback, causing it to wait indefinitely on itself. The attack vector is local and requires no authentication—any process performing filesystem operations on an NTFS volume can trigger this condition. The fix defers inode eviction by incrementing the reference count at the start of ntfs_writepages() and decrementing it at the end, ensuring writeback completes before eviction proceeds. Patches have been published in the stable kernel tree.
Affected products
- Linux Linux Kernel Multiple versions (patch available in stable branches)
Timeline
- 2026-08-15: disclosed: CVE-2026-72187 published
- 2026-07-02: patched: Original upstream fix committed
- 2026-07-24: patched: Fix merged to stable branches