๐Ÿ” CVE Alert

CVE-2026-72210

CRITICAL 9.8

ntfs: fix off-by-one in mapping pairs decoding bounds checks

CVSS Score
9.8
EPSS Score
0.5%
EPSS Percentile
42th

In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one in mapping pairs decoding bounds checks In ntfs_mapping_pairs_decompress(), attr_end points one byte past the end of the attribute record: attr_end = (u8 *)attr + le32_to_cpu(attr->length); The two bounds checks validating that mapping pair data bytes fit within the attribute use strict greater-than (>), which allows a one-byte out-of-bounds read when the data extends exactly to attr_end: b = *buf & 0xf; if (b) { if (unlikely(buf + b > attr_end)) // off-by-one goto io_error; for (deltaxcn = (s8)buf[b--]; b; b--) deltaxcn = (deltaxcn << 8) + buf[b]; } When buf + b == attr_end, the check evaluates to false and buf[b] reads one byte past the valid attribute boundary. The same pattern appears in the LCN delta bytes check. Fix both checks to use >= so that buf[b] at exactly attr_end is correctly rejected as out of bounds.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Last Updated Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
1e9ea7e04472d4e5e12e58c881eaacfb3e49b669 < bfe835e535fe0aa5767fdd8116f62e835ba50b55 1e9ea7e04472d4e5e12e58c881eaacfb3e49b669 < 18760a74ef7c28df93726445b5595162e62ed341
Linux / Linux
7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/bfe835e535fe0aa5767fdd8116f62e835ba50b55 git.kernel.org: https://git.kernel.org/stable/c/18760a74ef7c28df93726445b5595162e62ed341