Executive brief
The Linux kernel's NTFS filesystem implementation contains a race condition in the index reparenting process that can leave the filesystem index in a transiently corrupt state. When resizing NTFS index structures, the code publishes updated header metadata before ensuring the underlying data structure has been properly resized, allowing validation routines to reject the filesystem as corrupt even though the operation could succeed. This can cause filesystem errors and potential denial of service during routine NTFS operations on affected systems.
Technical details
This vulnerability exists in the ntfs_ir_reparent() function in fs/ntfs/index.c, which moves resident index root entries into an index block. The code publishes larger index.index_length and index.allocated_size header values before resizing the resident attribute value. If the resize operation returns -ENOSPC and recovery code calls ntfs_inode_add_attrlist(), the index root validation logic observes inconsistent state: the header claims 40 bytes of allocated space but the resident value only provides 32 bytes. The fix reorders operations so that when the root stub grows, the resident value is resized before the header is updated, ensuring consistent state during error recovery. The vulnerability is a logic/sequencing error rather than a memory safety issue, affecting NTFS filesystem reliability on Linux systems running affected kernel versions from v7.1 onwards.
Affected products
- Linux Linux kernel v7.1 and later
Timeline
- 2026-08-15: disclosed: CVE-2026-72211 published
- 2026-06-09: patched: Upstream patch commit 0bb508fb3b97e4802ec727fd2af4d608f65dd190
- 2026-07-24: patched: Stable kernel patch commit 38d444271604afc6381ddb5a181e391915c35fae