๐Ÿ” CVE Alert

CVE-2026-72198

HIGH 7.8

ntfs: reject non-resident records for resident-only attributes

CVSS Score
7.8
EPSS Score
0.2%
EPSS Percentile
5th

In the Linux kernel, the following vulnerability has been resolved: ntfs: reject non-resident records for resident-only attributes The shared lookup-time attribute validator rejects non-resident $FILE_NAME and $VOLUME_NAME records because their formats require resident values and callers handle returned records as resident attributes. Other resident-only attribute types still pass through the generic non-resident mapping-pairs checks. That leaves real resident/non-resident union confusion paths. Inode load looks up $STANDARD_INFORMATION and then reads data.resident.value_offset without checking a->non_resident. ntfs_inode_sync_standard_information() does the same when updating the standard information value. ntfs_write_volume_flags() also looks up $VOLUME_INFORMATION and reads data.resident.value_offset directly. $INDEX_ROOT callers in dir.c and index.c depend on the same lookup contract before consuming the resident index root value. Reject non-resident records for all resident-only attribute types in the shared validator. Keep the existing $FILE_NAME and $VOLUME_NAME behavior, but factor it through a helper and extend it to $STANDARD_INFORMATION, $OBJECT_ID, $VOLUME_INFORMATION, $INDEX_ROOT, and $EA_INFORMATION. For $OBJECT_ID and $EA_INFORMATION this is contract hardening for resident-only formats; this patch only rejects the non-resident form and does not add new resident value validation for those types.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Last Updated Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7ffa8f3d30236e0ab897c30bdb01224ff1fe1c89 1e9ea7e04472d4e5e12e58c881eaacfb3e49b669 < b54c9beb90e570bae17a9c18442aeeaf17165ccb 1e9ea7e04472d4e5e12e58c881eaacfb3e49b669 < 097cdfd0a55df5af82c9753833f39a8bfadbcfcb
Linux / Linux
2.6.12 7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/7ffa8f3d30236e0ab897c30bdb01224ff1fe1c89 git.kernel.org: https://git.kernel.org/stable/c/b54c9beb90e570bae17a9c18442aeeaf17165ccb git.kernel.org: https://git.kernel.org/stable/c/097cdfd0a55df5af82c9753833f39a8bfadbcfcb