{"id":"CVE-2026-72205","summary":"ntfs: free volume-wide resources on fill_super failure","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: free volume-wide resources on fill_super failure\n\nntfs_fill_super()'s err_out_now path frees only the volume struct via\nkfree(vol), leaving several vol-owned allocations behind on every mount\nfailure:\n\n  - vol-\u003enls_map, loaded by ntfs_init_fs_context() via\n    load_nls_default() (or replaced by an explicit nls= option in\n    ntfs_parse_param()), is never unload_nls()'d.\n\n  - vol-\u003evolume_label, allocated by load_system_files() through\n    ntfs_ucstonls() once the $Volume name attribute has been parsed, is\n    not released by load_system_files()'s own error labels nor by the\n    fill_super() inline cleanup that only runs on d_make_root()\n    failure.  Any later failure inside load_system_files() leaks it.\n\n  - vol-\u003elcn_empty_bits_per_page was kvfree()'d in\n    unl_upcase_iput_tmp_ino_err_out_now without clearing the pointer,\n    so it could not be folded into a single common cleanup.\n\nBecause the failure paths never call ntfs_volume_free() and never reach\nthe d_make_root() inline cleanup block (it sits above the label and is\njumped over by the load_system_files() / kvmalloc failure gotos), these\nresources accumulate per failed mount attempt with no chance of\nrecovery short of unloading the module.  This is a silent leak: the\ninodes loaded prior to failure remain hashed but generic_shutdown_super()\nskips evict_inodes() when sb-\u003es_root is unset, so no CHECK_DATA_CORRUPTION\nwarning is emitted either.\n\nMove the per-volume frees down to err_out_now and drop the\nlcn_empty_bits_per_page kvfree() from the upper label so the cleanup is\nperformed exactly once on every failure path.  Using unconditional\nkvfree() / kfree() / unload_nls() is safe because they all accept NULL\nand the upper labels that previously freed nls_map (the d_make_root()\ninline cleanup) already clear the pointer.","modified":"2026-08-20T03:30:17.204562030Z","published":"2026-08-15T05:54:01.803Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72205.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/a9523a7d3b24b3a6b25ec1eb668ee6618cacf05e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/aca3d383a23cb7f3a2849c09fda3974f1838d941"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72205.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72205"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6251f0b0de7d645e3591931ca4c11d8322c1866f"},{"fixed":"aca3d383a23cb7f3a2849c09fda3974f1838d941"},{"fixed":"a9523a7d3b24b3a6b25ec1eb668ee6618cacf05e"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72205.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.1.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72205.json"}}],"schema_version":"1.9.0"}