CVE-2026-72194: fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: add depth limit to indxfindbuffer to prevent stack overflow
indxfindbuffer() recursively descends the B+ tree index with no depth limit. A crafted NTFS image with circular index node references causes unbounded recursion, overflowing the kernel stack and panicking the system.
This is reachable by mounting a malicious NTFS filesystem (e.g. from a USB drive via desktop automount) and deleting a file whose index entry triggers the rebalancing fallback path in indxdeleteentry().
Add a depth parameter and bail out with -EINVAL when it reaches the fnd->nodes array bound, matching the constraint already enforced by fndpush() in indxfind().
The related function indxfind() was previously patched for a similar infinite-loop issue (commit 1732053c8a6b), but indxfindbuffer() was missed.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernel (fs/ntfs3)to a version that resolves this vulnerability.Patch 1732053c8a6b - Upgrade
Upgrade
Linux kernel (fs/ntfs3)to a version that resolves this vulnerability.Patch fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow - Configuration
Apply the fix so indx_find_buffer() tracks recursion depth and returns -EINVAL once the depth limit is reached, preventing unbounded recursion/stack overflow when mounting a malicious NTFS filesystem and deleting a file.
Linux kernel (fs/ntfs3) depth limit in indx_find_buffer()/indx_find() = bail out with -EINVAL when the depth parameter reaches the configured limit