CVE-2026-72208

Summary

In the Linux kernel, the following vulnerability has been resolved:

ntfs: add bounds check before accessing EA entries

in ntfs_ea_lookup and ntfs_listxattr, this verifies that there is enough space in the EA entry before accessing the next_entry_offset field of the EA entry.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d9d9925de1d8f233cc60d3dc356e12f232f97c15affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 937282f7d15b593d0be765fa2ced164130ec87f7affected
LinuxLinux0 < 7.1.5affected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References