AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72184

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's NTFS implementation, specifically in the handling of memory allocation during error processing in the `ntfs_non_resident_attr_insert_range()` function. If an error occurs while mapping the runlist, allocated memory for `hole_rl` is not properly freed, leading to a memory leak. System administrators and developers managing Linux systems with NTFS support should prioritize this issue to prevent potential resource exhaustion and ensure system stability.

CVE
CVE-2026-72184
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: ntfs: fix hole runlist memory leak in insert range error path ntfs_non_resident_attr_insert_range() allocates hole_rl before mapping the whole runlist. If ntfs_attr_map_whole_runlist() fails, the error path drops ni->runlist.lock and returns without freeing hole_rl. This leaks memory of sizeof(*hole_rl) * 2 bytes. Fix this memory leak by freeing hole_rl before returning from that error path, matching the later error paths in the same function.