CVE-2026-72200

Summary

In the Linux kernel, the following vulnerability has been resolved:

ntfs: detect mapping-pairs LCN accumulator overflow

The NTFS mapping-pairs parser accumulates relative LCN deltas in a signed integer. A corrupted attribute can drive that addition past the representable range.

One corrupt runlist shape sets the accumulated LCN to S64_MAX and then adds a delta of 1 in the next mapping-pairs entry.

Signed overflow is undefined and can turn an invalid runlist into a different set of physical clusters.

Check the LCN addition for overflow before storing the next run.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7fb64788812d137b37f6d8724e1e41c624c1e814affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ec4f061f2219e0f0c6465d56d0380bf749235a53affected
LinuxLinux0 < 7.1.5affected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References