« Volver al listado

CVE-2026-72193

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ntfs3: cap RESTART_TABLE free-chain walker at rt->used

A crafted NTFS3 disk image triggers an in-kernel infinite loop at mount time, hanging the mounting thread and firing the soft-lockup watchdog within ~22s on multi-CPU hosts (panic with kernel.softlockup_panic=1). The bug is reachable from desktop USB auto-mount on distributions where udisks2 routes the NTFS signature to the in-tree ntfs3 driver (Arch family and an increasing fraction of Fedora / openSUSE / RHEL deployments); CAP_SYS_ADMIN-class manual mount elsewhere.

check_rstbl()'s second walker iterates the free-entry singly-linked list headed by rt->first_free with no upper bound on iteration count:

Leer descripción completaMostrar menos

The existing guards cover three exits: end-of-list (off == 0), the in-use marker (off == RESTART_ENTRY_ALLOCATED), and out-of-bounds (off > ts - sizeof(__le32)). None of the three prevents an in-bounds cycle.

A crafted on-disk RESTART_TABLE whose free chain contains a self-loop or A->B->A cycle whose offsets satisfy:

passes all existing guards and spins the mount-time thread forever. Reproduced in UML by hand-forging a 2 MB NTFS3 image whose journal RESTART_TABLE first_free = 0x18 and whose entry at offset 0x18 stores 0x18 as its next pointer; mount of the forged image with the in-tree ntfs3 driver never returns.

Bound the walker by rt->used. Each entry on a legitimate free chain is unique, and the total slot count is ne = le16_to_cpu (rt->used). A traversal that visits more than ne slots is by construction malformed; reject it as a corrupt RESTART_TABLE.

After this patch, mount of the forged image returns with -EINVAL and a log_replay failure message, and mkntfs-produced legitimate images mount cleanly (verified in the same UML harness).

Detalles técnicos trazas, registros y código del informe original
  for (off = ff; off;) {
      if (off == RESTART_ENTRY_ALLOCATED)
          return false;
      off = le32_to_cpu(*(__le32 *)Add2Ptr(rt, off));
      if (off > ts - sizeof(__le32))
          return false;
  }

  - in range [sizeof(struct RESTART_TABLE), ts - sizeof(__le32)]
  - (off - sizeof(struct RESTART_TABLE)) % rsize == 0

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72193",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b46acd6a6a627d876898e1c84d3f84902264b445",
              "lessThan": "8128bec895075253c779d67afdc90ae513265fca",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b46acd6a6a627d876898e1c84d3f84902264b445",
              "lessThan": "7972df425687daa70d971fe6ed415e78683133dd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b46acd6a6a627d876898e1c84d3f84902264b445",
              "lessThan": "7ac4c86915c24c208a0f0611b71d9676686fe756",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b46acd6a6a627d876898e1c84d3f84902264b445",
              "lessThan": "29b86dbe88cbbef53bb9aaec2e279359f8c450f8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b46acd6a6a627d876898e1c84d3f84902264b445",
              "lessThan": "0fad25687d4d3fa1fdd313d31b9cb5817c425029",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b46acd6a6a627d876898e1c84d3f84902264b445",
              "lessThan": "d313416280d41bea272f02a6034dfa88008692a0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b46acd6a6a627d876898e1c84d3f84902264b445",
              "lessThan": "9611f644302c07d21bc8af97e3e06a3d30064253",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/ntfs3/fslog.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/ntfs3/fslog.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:37.797",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0fad25687d4d3fa1fdd313d31b9cb5817c425029",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/29b86dbe88cbbef53bb9aaec2e279359f8c450f8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7972df425687daa70d971fe6ed415e78683133dd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7ac4c86915c24c208a0f0611b71d9676686fe756",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8128bec895075253c779d67afdc90ae513265fca",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9611f644302c07d21bc8af97e3e06a3d30064253",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d313416280d41bea272f02a6034dfa88008692a0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs3: cap RESTART_TABLE free-chain walker at rt->used\n\nA crafted NTFS3 disk image triggers an in-kernel infinite loop at\nmount time, hanging the mounting thread and firing the soft-lockup\nwatchdog within ~22s on multi-CPU hosts (panic with\nkernel.softlockup_panic=1).  The bug is reachable from desktop USB\nauto-mount on distributions where udisks2 routes the NTFS signature\nto the in-tree ntfs3 driver (Arch family and an increasing fraction\nof Fedora / openSUSE / RHEL deployments); CAP_SYS_ADMIN-class manual\nmount elsewhere.\n\ncheck_rstbl()'s second walker iterates the free-entry singly-linked\nlist headed by rt->first_free with no upper bound on iteration count:\n\n  for (off = ff; off;) {\n      if (off == RESTART_ENTRY_ALLOCATED)\n          return false;\n      off = le32_to_cpu(*(__le32 *)Add2Ptr(rt, off));\n      if (off > ts - sizeof(__le32))\n          return false;\n  }\n\nThe existing guards cover three exits: end-of-list (off == 0), the\nin-use marker (off == RESTART_ENTRY_ALLOCATED), and out-of-bounds\n(off > ts - sizeof(__le32)).  None of the three prevents an\nin-bounds cycle.\n\nA crafted on-disk RESTART_TABLE whose free chain contains a\nself-loop or A->B->A cycle whose offsets satisfy:\n\n  - in range [sizeof(struct RESTART_TABLE), ts - sizeof(__le32)]\n  - (off - sizeof(struct RESTART_TABLE)) % rsize == 0\n\npasses all existing guards and spins the mount-time thread forever.\nReproduced in UML by hand-forging a 2 MB NTFS3 image whose journal\nRESTART_TABLE first_free = 0x18 and whose entry at offset 0x18\nstores 0x18 as its next pointer; mount of the forged image with\nthe in-tree ntfs3 driver never returns.\n\nBound the walker by rt->used.  Each entry on a legitimate free\nchain is unique, and the total slot count is ne = le16_to_cpu\n(rt->used).  A traversal that visits more than ne slots is by\nconstruction malformed; reject it as a corrupt RESTART_TABLE.\n\nAfter this patch, mount of the forged image returns with -EINVAL\nand a log_replay failure message, and mkntfs-produced legitimate\nimages mount cleanly (verified in the same UML harness)."
    }
  ],
  "lastModified": "2026-08-17T06:18:19.947",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}