fs/ntfs3: add bounds check to run_get_highest_vcn()
Summary
| CVE | CVE-2026-72478 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 06:22:21 UTC |
| Updated | 2026-08-17 06:19:15 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: add bounds check to run_get_highest_vcn() run_get_highest_vcn() parses a packed NTFS mapping-pairs buffer without any length bound, relying solely on a 0x00 terminator to stop. A crafted $LogFile UpdateMappingPairs record whose embedded attribute contains mapping-pairs runs without a terminator causes the function to read past the slab allocation, triggering a KASAN slab-out-of-bounds read on mount. The sibling function run_unpack() received an analogous bounds-check in commit b62567bca474 ("ntfs3: add buffer boundary checks to run_unpack()"), but run_get_highest_vcn() was missed. Take a run_buf_size parameter and reject any run header whose payload would extend past the buffer end, mirroring the pattern used by run_unpack(). The caller in fslog.c passes the remaining attribute bytes after the mapping-pairs offset. KASAN report (on mainline v7.1 merge window HEAD): BUG: KASAN: slab-out-of-bounds in run_get_highest_vcn+0x3c0/0x410 Read of size 1 at addr ffff88800e2d5400 by task mount/72 Call Trace: run_get_highest_vcn+0x3c0/0x410 do_action.isra.0+0x3ba8/0x7b50 log_replay+0x9ddd/0x10200 ntfs_loadlog_and_replay+0x4ad/0x610 ntfs_fill_super+0x214a/0x4540 |
Risk And Classification
Primary CVSS: v3.1 8.4 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.001540000 probability, percentile 0.050640000 (date 2026-08-17)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 8.4 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 8.4 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 425de2aba0d061b3e715d51a3b1992c112ed5b99 c69b9003332917b652175d5fa9d84158c5ed8617 git | Not specified |
| CNA | Linux | Linux | affected bf7ac4a1d3bfc6e56e54635c3d331a68170d37c9 8afc24a884aff6a6f08028bd779ee65c40054455 git | Not specified |
| CNA | Linux | Linux | affected e64f7dfcaff79e7dfff9121a382dd77f9b462f62 c23083b472a720c3f60b147db05b25b751c7c1bf git | Not specified |
| CNA | Linux | Linux | affected d3012690a7065d9ca86521a525ad11e8af491d45 a31893206588374d7d16fad387189d8165c7efd3 git | Not specified |
| CNA | Linux | Linux | affected b62567bca47408e6739dee75f02a2113548af875 41081202eb823f5b27ff164b12010b24428100ad git | Not specified |
| CNA | Linux | Linux | affected b62567bca47408e6739dee75f02a2113548af875 bb11485a87fbb2254b62cfed630b699d50e57da8 git | Not specified |
| CNA | Linux | Linux | affected bbad75336870b51b81979b97613746237fcb02fe git | Not specified |
| CNA | Linux | Linux | affected 41aadf5cb482793a24e05aa136224e179a778586 git | Not specified |
| CNA | Linux | Linux | affected 6.1.175 6.1.178 semver | Not specified |
| CNA | Linux | Linux | affected 6.6.140 6.6.145 semver | Not specified |
| CNA | Linux | Linux | affected 6.12.86 6.12.97 semver | Not specified |
| CNA | Linux | Linux | affected 6.18.27 6.18.40 semver | Not specified |
| CNA | Linux | Linux | affected 5.15.209 5.16 semver | Not specified |
| CNA | Linux | Linux | affected 7.0.4 7.1 semver | Not specified |
| CNA | Linux | Linux | affected 7.1 | Not specified |
| CNA | Linux | Linux | unaffected 7.1 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.178 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.145 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.97 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.40 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.5 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/c69b9003332917b652175d5fa9d84158c5ed8617 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/a31893206588374d7d16fad387189d8165c7efd3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c23083b472a720c3f60b147db05b25b751c7c1bf | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/8afc24a884aff6a6f08028bd779ee65c40054455 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/bb11485a87fbb2254b62cfed630b699d50e57da8 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/41081202eb823f5b27ff164b12010b24428100ad | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.