{"id":"CVE-2026-72186","summary":"ntfs: make system files immutable to prevent corruption","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: make system files immutable to prevent corruption\n\nWhen a system file such as $Bitmap is exposed via show_sys_files and\nwritten from userspace, the volume is corrupted and, because the cluster\nallocator scans $Bitmap through the same inode's page cache, a write to\n$Bitmap also deadlocks writeback against the folio it already holds locked.\n\nThese files are maintained by the driver itself and have no valid reason\nto be written through the file interface. Mark base metadata files\n(mft_no \u003c FILE_first_user) as immutable during inode read so the VFS\nrejects write, mmap, truncate and unlink with -EPERM. Directories are\nskipped so the root and $Extend remain usable. Internal metadata updates\ndo not go through the VFS write path and are unaffected.","modified":"2026-08-18T03:56:38.262360650Z","published":"2026-08-15T05:53:48.127Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72186.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/8f313e92522ac41d273ea137db13ea8a8df2beed"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f72df3a4c33b64de3418ec74d1ad4f028e09d161"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72186.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72186"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"af0db57d4293cc9fe6ce99fb5592dc2652228c9d"},{"fixed":"8f313e92522ac41d273ea137db13ea8a8df2beed"},{"fixed":"f72df3a4c33b64de3418ec74d1ad4f028e09d161"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72186.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.1.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72186.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}