Junglewise Threat Intelligence

CVE-2026-72197: Linux kernel NTFS3 out-of-bounds memmove in DeleteIndexEntryAllocation

CVE-2026-72197 · Severity: high · CVSS 8.4 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NTFS3 file system driver contains a buffer overflow vulnerability in its NTFS journal processing code. A malicious or corrupted NTFS disk image can trigger an out-of-bounds memory write when the kernel attempts to delete an index entry, potentially causing a kernel crash or allowing privilege escalation. Systems that mount untrusted NTFS volumes are at risk.

Technical details

This is a heap buffer overflow in fs/ntfs3/fslog.c within the do_action() function's DeleteIndexEntryAllocation case. The vulnerability occurs when processing INDEX_BUFFER entries with crafted sizes: an attacker-controlled e->size value can cause pointer arithmetic to underflow, resulting in a negative ptrdiff_t that is silently cast to a quasi-infinite size_t. This enormous size is then passed to memmove(), which writes far past the destination buffer boundary. The fix adds three validation guards: rejecting zero-sized entries, ensuring the entry endpoint does not exceed the used buffer boundary, and checking the computed memmove length is valid. The vulnerability requires local access (mounting a crafted disk image) and is reproducible via UML+KASAN with a malformed NTFS image.

Affected products

  • Linux Linux kernel all versions with NTFS3 support (Linux 5.15+)

Timeline

  • 2026-08-15: disclosed
  • 2026-07-24: patched: Fix committed upstream; distributed to stable branches

References

Related threats