CVE-2026-63793

Summary

In the Linux kernel, the following vulnerability has been resolved:

ntfs: serialize volume label accesses

Protect vol->volume_label with a mutex and snaphost the label before copy_to_user. This prevent a use-after-free when FS_IOC_SETFSLABEL replaces the vol->volume_label and FS_IOC_GETTSLABEL reads it concurrently.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux9c87959601e80b39a45250e362e6ddfec17cb0fa < acd744019460bad22e43d4569a502f9c88d331aeaffected
LinuxLinux9c87959601e80b39a45250e362e6ddfec17cb0fa < e9e50ce4f13dc721014af622613409455c734942affected
LinuxLinux7.1affected
LinuxLinux0 < 7.1unaffected
LinuxLinux7.1.3 <= 7.1.*unaffected
LinuxLinux7.2-rc1 <= *unaffected

Weaknesses

References