SB20260816342 - Stack-based buffer overflow in Linux kernel ntfs3
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Stack-based buffer overflow (CVE-ID: CVE-2026-72194)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in indx_find_buffer() in the ntfs3 filesystem driver when mounting a crafted NTFS filesystem and deleting a file that triggers index rebalancing. An attacker with physical access can provide a malicious NTFS image with circular index node references to cause a denial of service.
User interaction may be required in environments where removable media is mounted through desktop automount.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1ebd684b8f627f75bc3e03f8b2ad8400fd1f02cd
- https://git.kernel.org/stable/c/65357a81f64cb3fbe13b4b937586755e4b3a072f
- https://git.kernel.org/stable/c/78612f478f9fadcec4f9b3b089970da67ffb47e9
- https://git.kernel.org/stable/c/908c9243ba309997b73cbda3e4c563d0fb345ee9
- https://git.kernel.org/stable/c/96fb64f9da86fd2dbd78fbe9d9e41ae27e12ce34
- https://git.kernel.org/stable/c/99031d4f63c785d2a985b6a4c64c4256f7117052
- https://git.kernel.org/stable/c/fdf50c788e0991e42a187ff75479a0df7fb752f1