Out-of-bounds read in Linux kernel - CVE-2026-72478
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in run_get_highest_vcn() when mounting an NTFS filesystem containing a crafted $LogFile UpdateMappingPairs record with unterminated mapping-pairs data. A remote attacker can provide a specially crafted filesystem image to cause a denial of service.
The issue is triggered during log replay on mount.
Affected software
openEuler
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-extra-modules
kernel-headers
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo
How to mitigate CVE-2026-72478
kernel - update to 6.6.0-145.3.29.160
bpftool - update to 6.6.0-145.3.29.160
bpftool-debuginfo - update to 6.6.0-145.3.29.160
kernel-debuginfo - update to 6.6.0-145.3.29.160
kernel-debugsource - update to 6.6.0-145.3.29.160
kernel-devel - update to 6.6.0-145.3.29.160
kernel-extra-modules - update to 6.6.0-145.3.29.160
kernel-headers - update to 6.6.0-145.3.29.160
kernel-source - update to 6.6.0-145.3.29.160
kernel-tools - update to 6.6.0-145.3.29.160
kernel-tools-debuginfo - update to 6.6.0-145.3.29.160
kernel-tools-devel - update to 6.6.0-145.3.29.160
perf - update to 6.6.0-145.3.29.160
perf-debuginfo - update to 6.6.0-145.3.29.160
python3-perf - update to 6.6.0-145.3.29.160
python3-perf-debuginfo - update to 6.6.0-145.3.29.160
External References
- https://git.kernel.org/stable/c/41081202eb823f5b27ff164b12010b24428100ad
- https://git.kernel.org/stable/c/8afc24a884aff6a6f08028bd779ee65c40054455
- https://git.kernel.org/stable/c/a31893206588374d7d16fad387189d8165c7efd3
- https://git.kernel.org/stable/c/bb11485a87fbb2254b62cfed630b699d50e57da8
- https://git.kernel.org/stable/c/c23083b472a720c3f60b147db05b25b751c7c1bf
- https://git.kernel.org/stable/c/c69b9003332917b652175d5fa9d84158c5ed8617