ZDI-CAN-30226: ZDI-26-696: Linux Kernel NTFS3 Journal Heap-based Buffer Overflow Code Execution Vulnerability
Published Sep 14, 2026
·Updated
This vulnerability allows local attackers to execute arbitrary code on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-72196.
Affected Software
1 affected component
Linux Linux kernel
Event History
Sep 14, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Who is exposed to this vulnerability?
Affected Linux kernel installations are exposed if an attacker can already execute low-privileged code locally on the system. It is not described as remotely exploitable from the provided information.
2
What access does an attacker need to exploit it?
The attacker must first be able to run low-privileged code on the target system. Successful exploitation can allow arbitrary code execution.