8.4

CVE-2026-72196

fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass

In log_replay()'s analysis pass, after find_dp() returns a
valid DIR_PAGE_ENTRY for the (target_attr, target_vcn) tuple,
the copy_lcns block walks lrh->lcns_follow further entries:

	t16 = le16_to_cpu(lrh->lcns_follow);
	for (i = 0; i < t16; i++) {
	    size_t j = (size_t)(le64_to_cpu(lrh->target_vcn) -
	                        le64_to_cpu(dp->vcn));
	    dp->page_lcns[j + i] = lrh->page_lcns[i];
	}

find_dp() only validates that target_vcn falls within
[dp->vcn, dp->vcn + dp->lcns_follow), i.e., that the FIRST
cluster is covered.  The walk through the further entries is
not bounded against dp->lcns_follow.  For a malformed LRH
where target_vcn = dp->vcn + dp->lcns_follow - 1 and
lrh->lcns_follow > 1, the i > 0 writes overflow the dp's
allocated page_lcns[] array.

Add the missing j + lrh->lcns_follow <= dp->lcns_follow guard.

Reproduced under UML+KASAN on mainline 8d90b09e6741 as a
slab-out-of-bounds write of size 8 from log_replay+0x68d4 on
the mount path.

This is distinct from Pavitra Jha's 2026-05-02 patch
("fs/ntfs3: validate lcns_follow in log_replay conversion",
<20260502154252.164586-1-jhapavitra98@gmail.com>) which
addresses the separate version-0 dirty-page-table conversion
path's memmove(&dp->vcn, ...) call.  The two fixes are
complementary; both should land.

[almaz.alexandrovich@paragon-software.com: clang-formatted the changes,
fixed conflicts]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b46acd6a6a627d876898e1c84d3f84902264b445
Version < 9b3d8cc9d54fcded4de51b2b1026ae7182512077
Status affected
Version b46acd6a6a627d876898e1c84d3f84902264b445
Version < 9b7c28d8c61bdb041936222a09a708531a1c2921
Status affected
Version b46acd6a6a627d876898e1c84d3f84902264b445
Version < 0f13e823bf86bd1800168ea0bb5bca8b8500a81c
Status affected
Version b46acd6a6a627d876898e1c84d3f84902264b445
Version < d240cd98f5f7b65c90f6b2b6abe3232ccdc405ab
Status affected
Version b46acd6a6a627d876898e1c84d3f84902264b445
Version < 49c86dae0c0ccb8d98ddcdc46987259389c816dd
Status affected
Version b46acd6a6a627d876898e1c84d3f84902264b445
Version < 5e7b598660cfa8e5af172cf4c65cffc126333307
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.081
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9b3d8cc9d54fcded4de51b2b1026ae7182512077
https://git.kernel.org/stable/c/9b7c28d8c61bdb041936222a09a708531a1c2921
https://git.kernel.org/stable/c/0f13e823bf86bd1800168ea0bb5bca8b8500a81c
https://git.kernel.org/stable/c/d240cd98f5f7b65c90f6b2b6abe3232ccdc405ab
https://git.kernel.org/stable/c/49c86dae0c0ccb8d98ddcdc46987259389c816dd
https://git.kernel.org/stable/c/5e7b598660cfa8e5af172cf4c65cffc126333307