From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A66783043CF for ; Sat, 15 Aug 2026 06:15:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786774526; cv=none; b=Xu8tOjWmyx8CmIUX66CVV2fRjwBHpImIqM+gZWj68lMBiw6z6GXMzvWUqXI6bGDXNgyx+6dMBCPnZl19ZAJA0R7WXkAzRKitL4Yhioq5q1qvOz/nkqWH7UZUUj0eA61OuUcPUQcRv9CpFpel88VOshnrwR5hFELrJG5e3SuWWEI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786774526; c=relaxed/simple; bh=iPYHQPLofeF/qFubxH2ia4VINTGL2/K24aAopCXxL+4=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=P3LBm8IORF/M33EbzP/gcR8VyCxdxLPoNp+h7WD37TUwWgp/H4vJC04l4WW0++Mx+H0x9+Ojb+FiQDHICGahotGa9CJj/cXe/St31TCILG4jdDX8j/sFvFe+WsiLSnq+D2HBLO4fp0Iyu3dimcN+LcoT0/cIgdpn1e4G3U1tKlk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=OAWeQB2M; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="OAWeQB2M" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 052721F000E9; Sat, 15 Aug 2026 06:15:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786774525; bh=0xXSe8W+0B65vz1MTU4A4pYdaVq0SIXnTKH7eJ3Ci1A=; h=From:To:Cc:Subject:Date:Reply-To; b=OAWeQB2M3H2Kxzu56q5linktKYc+Ag8iX81d6wQz8awPw6eZZJ4IJpEC2nvXWvB// qStpBEf6ekQmoj9mJ3iwmk+IKb95D97rX/EpfTDZ4rZHZa97xtFi/OlHwZFOgjaRDU A6gA1dWCSgI8Vyh5mEDsgwICqMMJhPELBlQ7goIY= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-72185: ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() Date: Sat, 15 Aug 2026 15:04:24 +0900 Message-ID: <2026081540-CVE-2026-72185-c4f6@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3119; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=Y1WUQnMBR0clhL0f/GI4MkaqmHWgAZI8tEk9oIQNsPk=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkNDEf+da0SWXOj98bZndFnH2bKl2ctNTr7+PhZN7FXB 4r9LxmLdsSyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBEdAoY5qnozKrx/9umLNhh Vfhj+ZnXBgt7VRnmR2040Xvk9OyqRTKF7z8G9vfZbotrBQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() When ntfs_map_runlist_nolock() needs to look up the attribute extent containing a target VCN (ctx_needs_reset == true), it calls ntfs_attr_lookup() and then expects the result to be a non-resident attribute, since only non-resident attributes have a mapping pairs array to decompress. A crafted NTFS image can place a resident attribute where a non-resident one is expected, causing ntfs_attr_lookup() to succeed but return a resident attribute record. Previously this was caught only by a WARN_ON(), which does not stop execution. The code then falls through to read a->data.non_resident.highest_vcn from what is actually a resident attribute, accessing the wrong union member and corrupting the VCN range check. The caller path triggering this warning during mount is: ntfs_map_runlist_nolock ntfs_empty_logfile load_system_files ntfs_fill_super In this path ctx is NULL, so ntfs_map_runlist_nolock() allocates a temporary search context internally and sets ctx_needs_reset = true. The existing resident-attribute guard in the ctx != NULL branch already returns -EIO silently for the same condition; make the ctx_needs_reset path consistent by replacing the WARN_ON() with the same -EIO error return. This causes the crafted image to be rejected with a mount error instead of triggering a kernel warning. The Linux kernel CVE team has assigned CVE-2026-72185 to this issue. Affected and fixed versions =========================== Issue introduced in 7.1 with commit 495e90fa334828d4119061e2726af51d0a0fb4ed and fixed in 7.1.5 with commit b397b1238a217264bb02f963a1a1eadf71906375 Issue introduced in 7.1 with commit 495e90fa334828d4119061e2726af51d0a0fb4ed and fixed in 7.2-rc3 with commit b8d6c528e9d57d263fee1a648409f84a68b2561d Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-72185 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/ntfs/attrib.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/b397b1238a217264bb02f963a1a1eadf71906375 https://git.kernel.org/stable/c/b8d6c528e9d57d263fee1a648409f84a68b2561d