Junglewise Threat Intelligence

CVE-2026-72202: Linux kernel NTFS heap allocation denial of service

CVE-2026-72202 · Severity: high · CVSS 7.5 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NTFS filesystem driver contains a flaw in memory allocation for cluster readahead operations. When the kernel fails to allocate temporary memory during filesystem operations, it returns without notifying waiting processes, causing them to hang indefinitely. This can lead to system hangs or application freezes when NTFS volumes are accessed under memory pressure.

Technical details

The vulnerability is a denial-of-service condition in the NTFS driver's get_nr_free_clusters() and __get_nr_free_mft_records() functions. Both functions attempted to allocate a file_ra_state structure on the heap via kzalloc(). When this allocation failed, the functions would return early without setting the NVolFreeClusterKnown flag or waking the vol->free_waitq waitqueue, causing callers waiting for the free cluster count to block indefinitely. The fix moves the file_ra_state structure from heap allocation to stack allocation, eliminating the allocation failure path entirely. This affects kernel versions 7.1 and later; no authentication is required—any local process accessing an NTFS filesystem can trigger the condition.

Affected products

  • Linux Linux kernel 7.1 and later

Timeline

  • 2026-08-15: disclosed
  • 2026-07-24: patched

References

Related threats