Answer in brief
CVE-2026-72200 records a Critical severity (CVSS 9.8) vulnerability in ntfs: detect mapping-pairs LCN accumulator overflow. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7fb64788812d137b37f6d8724e1e41c624c1e814 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <ec4f061f2219e0f0c6465d56d0380bf749235a53 || >=0 <7.1.5 | 7fb64788812d137b37f6d8724e1e41c624c1e814, ec4f061f2219e0f0c6465d56d0380bf749235a53, 7.1.5 |
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7fb64788812d137b37f6d8724e1e41c624c1e814 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <ec4f061f2219e0f0c6465d56d0380bf749235a53 | 7fb64788812d137b37f6d8724e1e41c624c1e814, ec4f061f2219e0f0c6465d56d0380bf749235a53 |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7ffa8f3d30236e0ab897c30bdb01224ff1fe1c89 || >=1e9ea7e04472d4e5e12e58c881eaacfb3e49b669 <7fb64788812d137b37f6d8724e1e41c624c1e814 || >=1e9ea7e04472d4e5e12e58c881eaacfb3e49b669 <ec4f061f2219e0f0c6465d56d0380bf749235a53 | 7ffa8f3d30236e0ab897c30bdb01224ff1fe1c89, 7fb64788812d137b37f6d8724e1e41c624c1e814, ec4f061f2219e0f0c6465d56d0380bf749235a53 |
| Linux/Linuxgeneric | 2.6.12 || 7.1 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: ntfs: detect mapping-pairs LCN accumulator overflow The NTFS mapping-pairs parser accumulates relative LCN deltas in a signed integer. A corrupted attribute can drive that addition past the representable range. One corrupt runlist shape sets the accumulated LCN to S64_MAX and then adds a delta of 1 in the next mapping-pairs entry. Signed overflow is undefined and can turn an invalid runlist into a different set of physical clusters. Check the LCN addition for overflow before storing the next run.
Quoted source text, attributed separately from HOL analysis.