← Voltar à pesquisa de CVEs

CVE-2026-72200

Linux kernel

Descrição

In the Linux kernel, the following vulnerability has been resolved: ntfs: detect mapping-pairs LCN accumulator overflow The NTFS mapping-pairs parser accumulates relative LCN deltas in a signed integer. A corrupted attribute can drive that addition past the representable range. One corrupt runlist shape sets the accumulated LCN to S64_MAX and then adds a delta of 1 in the next mapping-pairs entry. Signed overflow is undefined and can turn an invalid runlist into a different set of physical clusters. Check the LCN addition for overflow before storing the next run.

CVSS 9.8EPSS 0.598%Risco 1.03
Ver fonte
Publicação
2026-08-15 06:21:38
Versões afetadas
unknown
Tipo
Kernel
Última alteração
2026-08-19 08:17:13
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H