CVE-2026-72200

Summary

In the Linux kernel, the following vulnerability has been resolved:

ntfs: detect mapping-pairs LCN accumulator overflow

The NTFS mapping-pairs parser accumulates relative LCN deltas in a signed integer. A corrupted attribute can drive that addition past the representable range.

One corrupt runlist shape sets the accumulated LCN to S64_MAX and then adds a delta of 1 in the next mapping-pairs entry.

Signed overflow is undefined and can turn an invalid runlist into a different set of physical clusters.

Check the LCN addition for overflow before storing the next run.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7ffa8f3d30236e0ab897c30bdb01224ff1fe1c89affected
LinuxLinux1e9ea7e04472d4e5e12e58c881eaacfb3e49b669 < 7fb64788812d137b37f6d8724e1e41c624c1e814affected
LinuxLinux1e9ea7e04472d4e5e12e58c881eaacfb3e49b669 < ec4f061f2219e0f0c6465d56d0380bf749235a53affected
LinuxLinux2.6.12affected
LinuxLinux7.1affected
LinuxLinux0 < 2.6.12unaffected
LinuxLinux6.9 < 7.1unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References