CVE-2026-72196

Source
https://cve.org/CVERecord?id=CVE-2026-72196
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72196.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72196
Downstream
Published
2026-08-15T05:53:55Z
Modified
2026-08-18T03:56:38Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
Details

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass

In log_replay()'s analysis pass, after find_dp() returns a valid DIR_PAGE_ENTRY for the (target_attr, target_vcn) tuple, the copy_lcns block walks lrh->lcns_follow further entries:

t16 = le16_to_cpu(lrh->lcns_follow);
for (i = 0; i < t16; i++) {
    size_t j = (size_t)(le64_to_cpu(lrh->target_vcn) -
                        le64_to_cpu(dp->vcn));
    dp->page_lcns[j + i] = lrh->page_lcns[i];
}

find_dp() only validates that target_vcn falls within [dp->vcn, dp->vcn + dp->lcns_follow), i.e., that the FIRST cluster is covered. The walk through the further entries is not bounded against dp->lcns_follow. For a malformed LRH where target_vcn = dp->vcn + dp->lcns_follow - 1 and lrh->lcns_follow > 1, the i > 0 writes overflow the dp's allocated page_lcns[] array.

Add the missing j + lrh->lcns_follow <= dp->lcns_follow guard.

Reproduced under UML+KASAN on mainline 8d90b09e6741 as a slab-out-of-bounds write of size 8 from log_replay+0x68d4 on the mount path.

This is distinct from Pavitra Jha's 2026-05-02 patch ("fs/ntfs3: validate lcns_follow in log_replay conversion", 20260502154252.164586-1-jhapavitra98@gmail.com) which addresses the separate version-0 dirty-page-table conversion path's memmove(&dp->vcn, ...) call. The two fixes are complementary; both should land.

[almaz.alexandrovich@paragon-software.com: clang-formatted the changes, fixed conflicts]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72196.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b46acd6a6a627d876898e1c84d3f84902264b445
Fixed
9b3d8cc9d54fcded4de51b2b1026ae7182512077
Fixed
9b7c28d8c61bdb041936222a09a708531a1c2921
Fixed
0f13e823bf86bd1800168ea0bb5bca8b8500a81c
Fixed
d240cd98f5f7b65c90f6b2b6abe3232ccdc405ab
Fixed
49c86dae0c0ccb8d98ddcdc46987259389c816dd
Fixed
5e7b598660cfa8e5af172cf4c65cffc126333307

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72196.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72196.json"