{"api_version":"1","generated_at":"2026-08-18T11:34:22+00:00","cve":"CVE-2026-72201","urls":{"html":"https://cve.report/CVE-2026-72201","api":"https://cve.report/api/cve/CVE-2026-72201.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-72201","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-72201"},"summary":{"title":"ntfs: validate index entries on reading","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: validate index entries on reading\n\nValidate index entries immediately after reading an index root or index\nblock from disk. This eliminates repeated checks in lookup and readdir,\nand reduce the risk of missing checks in those paths.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 06:21:38","updated_at":"2026-08-18 07:16:53"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/2221b691d7b2e17f08153f95848dacaa5d87e21d","name":"https://git.kernel.org/stable/c/2221b691d7b2e17f08153f95848dacaa5d87e21d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e2b95d3adb558ddd5685f9e072ec8661d57ee3a9","name":"https://git.kernel.org/stable/c/e2b95d3adb558ddd5685f9e072ec8661d57ee3a9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-72201","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72201","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0a8ac0c1fa0b99a5b29002bc7f232ed7eafddef0 e2b95d3adb558ddd5685f9e072ec8661d57ee3a9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0a8ac0c1fa0b99a5b29002bc7f232ed7eafddef0 2221b691d7b2e17f08153f95848dacaa5d87e21d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.1","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"72201","cve":"CVE-2026-72201","epss":"0.005160000","percentile":"0.415490000","score_date":"2026-08-17","updated_at":"2026-08-18 00:11:47"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/ntfs/dir.c","fs/ntfs/index.c","fs/ntfs/index.h","fs/ntfs/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"e2b95d3adb558ddd5685f9e072ec8661d57ee3a9","status":"affected","version":"0a8ac0c1fa0b99a5b29002bc7f232ed7eafddef0","versionType":"git"},{"lessThan":"2221b691d7b2e17f08153f95848dacaa5d87e21d","status":"affected","version":"0a8ac0c1fa0b99a5b29002bc7f232ed7eafddef0","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/ntfs/dir.c","fs/ntfs/index.c","fs/ntfs/index.h","fs/ntfs/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.1"},{"lessThan":"7.1","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"7.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"7.1","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: validate index entries on reading\n\nValidate index entries immediately after reading an index root or index\nblock from disk. This eliminates repeated checks in lookup and readdir,\nand reduce the risk of missing checks in those paths."}],"metrics":[{"cvssV3_1":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - Crafted NTFS index entries are parsed when nfsd or ksmbd serves READDIR/LOOKUP on an exported legacy NTFS mount and via local getdents/open/stat; ntfs_readdir, ntfs_lookup_inode_by_name, and ntfs_index_lookup all walk INDX metadata read from disk.\nAC:L - Attackers fully control on-disk INDX/$INDEX_ROOT entry length, key_length, and file_name fields in a malicious image or writable share, so out-of-bounds walks in ntfs_index_next, ntfs_ie_lookup, and ntfs_index_walk_down are reliably triggerable without races or attacker-independent layout.\nPR:N - No victim account or capability is required when a malicious NTFS volume is automounted from USB, dual-boot, or loopback by root/udisks2; unprivileged NFS/SMB clients can also trigger directory walks on exported poisoned mounts without host privileges.\nUI:N - Kiosks, desktops, and embedded systems that automount removable NTFS media run ntfs_fill_super and directory index reads on insertion alone; subsequent readdir/lookup walks need no further deliberate victim interaction beyond presenting the volume.\nS:U - Impact is kernel heap out-of-bounds access within the host OS parsing context; exploitation yields local privilege escalation, not VM escape, IOMMU bypass, or another cross-authority sandbox boundary.\nC:H - Missing per-entry validation lets attacker-controlled key_length and file_name_length drive ntfs_collate, ntfs_ucstonls, and ntfs_index_next past INDX/$INDEX_ROOT buffers, enabling out-of-bounds kernel memory reads and potential pointer disclosure.\nI:H - Attacker-controlled ie->length and key fields advance index pointers and kmalloc/copy sizes in ntfs_readdir and ntfs_index_lookup, corrupting kmalloc slabs and enabling heap overwrite primitives suitable for kernel code execution.\nA:H - Out-of-bounds index entry walks during mount, readdir, or lookup can fault on unmapped kernel memory and trigger BUG/oops/panic, fully denying system availability even before successful exploitation."}]}],"providerMetadata":{"dateUpdated":"2026-08-18T06:56:18.944Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/e2b95d3adb558ddd5685f9e072ec8661d57ee3a9"},{"url":"https://git.kernel.org/stable/c/2221b691d7b2e17f08153f95848dacaa5d87e21d"}],"title":"ntfs: validate index entries on reading","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-72201","datePublished":"2026-08-15T05:53:58.854Z","dateReserved":"2026-08-09T03:40:39.912Z","dateUpdated":"2026-08-18T06:56:18.944Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:21:38","lastModifiedDate":"2026-08-18 07:16:53","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"72201","Ordinal":"1","Title":"ntfs: validate index entries on reading","CVE":"CVE-2026-72201","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"72201","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: validate index entries on reading\n\nValidate index entries immediately after reading an index root or index\nblock from disk. This eliminates repeated checks in lookup and readdir,\nand reduce the risk of missing checks in those paths.","Type":"Description","Title":"ntfs: validate index entries on reading"}]}}}