CVE-2026-72185: ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock()

Published Aug 15, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ntfs: fix WARNON for resident attribute in ntfsmaprunlistnolock()

When ntfsmaprunlistnolock() needs to look up the attribute extent containing a target VCN (ctxneedsreset == true), it calls ntfsattrlookup() and then expects the result to be a non-resident attribute, since only non-resident attributes have a mapping pairs array to decompress.

A crafted NTFS image can place a resident attribute where a non-resident one is expected, causing ntfsattrlookup() to succeed but return a resident attribute record. Previously this was caught only by a WARNON(), which does not stop execution. The code then falls through to read a->data.nonresident.highestvcn from what is actually a resident attribute, accessing the wrong union member and corrupting the VCN range check.

The caller path triggering this warning during mount is:

ntfsmaprunlistnolock ntfsemptylogfile loadsystemfiles ntfsfillsuper

In this path ctx is NULL, so ntfsmaprunlistnolock() allocates a temporary search context internally and sets ctxneedsreset = true. The existing resident-attribute guard in the ctx != NULL branch already returns -EIO silently for the same condition; make the ctxneedsreset path consistent by replacing the WARNON() with the same -EIO error return.

This causes the crafted image to be rejected with a mount error instead of triggering a kernel warning.

Affected Software

1 affected component
Linux Linux kernel

Event History

Aug 15, 2026
CVE Published
via MITRE·05:53 AM
Data Sourced
via MITRE·05:53 AM
Description
Data Sourced
via NVD·06:21 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-72185?

CVE-2026-72185 has a risk rating of 23, indicating it is a significant vulnerability.

2

How do I fix CVE-2026-72185?

To fix CVE-2026-72185, update your Linux kernel to the latest version that includes the fix.

3

What systems are affected by CVE-2026-72185?

CVE-2026-72185 affects systems using the NTFS filesystem within the Linux kernel.

4

What impact does CVE-2026-72185 have on system performance?

CVE-2026-72185 may lead to unexpected warnings during the handling of resident attributes in NTFS.

5

When was CVE-2026-72185 published?

CVE-2026-72185 was published on August 15, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203