{"id":"DEBIAN-CVE-2026-72354","details":"In the Linux kernel, the following vulnerability has been resolved:  ntfs: avoid stale runlist element dereference in MFT writeback  ntfs_write_mft_block() maps each $MFT record through the $MFT data runlist. For sub-folio clusters it looks up a struct runlist_element under ni-\u003erunlist.lock, drops the lock, and later uses rl-\u003elength and rl-\u003evcn when choosing folio_sz.  That pointer is only borrowed from ni-\u003erunlist.rl. Concurrent $MFT allocation extension can merge a replacement runlist under the same lock, and ntfs_rl_realloc() can free the old backing array. If that happens between the lookup and the later folio_sz decision, writeback can dereference freed runlist storage.  The buggy scenario involves two paths, with each column showing the order within that path:  MFT writeback path:               $MFT allocation extension: 1. Look up rl under               1. Extend the $MFT data allocation.    ni-\u003erunlist.lock.              2. Publish a replacement runlist. 2. Drop ni-\u003erunlist.lock.         3. Free the old runlist array. 3. Read rl-\u003elength and rl-\u003evcn    to choose folio_sz.  Compute the remaining run length while ni-\u003erunlist.lock is still held, and use that scalar after unlock. This preserves the existing folio sizing decision without carrying a borrowed runlist_element across the lock boundary.  Validation reproduced this kernel report: BUG: KASAN: slab-use-after-free in ntfs_mft_writepages+0x1c8d/0x1fb0  Call Trace:  \u003cTASK\u003e  dump_stack_lvl+0x66/0xa0  print_report+0xce/0x630  ? ntfs_mft_writepages+0x1c8d/0x1fb0  ? srso_alias_return_thunk+0x5/0xfbef5  ? __virt_addr_valid+0x20d/0x410  ? ntfs_mft_writepages+0x1c8d/0x1fb0  kasan_report+0xe0/0x110  ? ntfs_mft_writepages+0x1c8d/0x1fb0  ntfs_mft_writepages+0x1c8d/0x1fb0  ? __pfx_ntfs_mft_writepages+0x10/0x10  ? __pfx___mutex_unlock_slowpath+0x10/0x10  ? srso_alias_return_thunk+0x5/0xfbef5  ? iput+0x92/0xa80  do_writepages+0x219/0x530  ? __pfx_do_writepages+0x10/0x10  __writeback_single_inode+0x117/0xf50  ? do_raw_spin_lock+0x130/0x270  ? __pfx_do_raw_spin_lock+0x10/0x10  ? __pfx___writeback_single_inode+0x10/0x10  ? srso_alias_return_thunk+0x5/0xfbef5  writeback_sb_inodes+0x65b/0x1810  ? srso_alias_return_thunk+0x5/0xfbef5  ? lock_acquire+0x2b8/0x2f0  ? __pfx_writeback_sb_inodes+0x10/0x10  ? lock_release+0x1e0/0x280  ? _raw_spin_unlock+0x23/0x40  ? move_expired_inodes+0x2b8/0x850  __writeback_inodes_wb+0xf4/0x270  ? __pfx___writeback_inodes_wb+0x10/0x10  ? srso_alias_return_thunk+0x5/0xfbef5  ? queue_io+0x2e4/0x410  wb_writeback+0x666/0x880  ? srso_alias_return_thunk+0x5/0xfbef5  ? __pfx_wb_writeback+0x10/0x10  ? srso_alias_return_thunk+0x5/0xfbef5  ? srso_alias_return_thunk+0x5/0xfbef5  ? get_nr_dirty_inodes+0x1c/0x170  wb_workfn+0x75e/0xbb0  ? srso_alias_return_thunk+0x5/0xfbef5  ? _raw_spin_unlock_irqrestore+0x27/0x60  ? __pfx_wb_workfn+0x10/0x10  ? __pfx_debug_object_deactivate+0x10/0x10  ? lock_acquire+0x2b8/0x2f0  ? srso_alias_return_thunk+0x5/0xfbef5  ? lock_release+0x1e0/0x280  process_one_work+0x8d0/0x1870  ? __pfx_process_one_work+0x10/0x10  ? srso_alias_return_thunk+0x5/0xfbef5  worker_thread+0x575/0xf80  ? __pfx_worker_thread+0x10/0x10  kthread+0x2e7/0x3c0  ? __pfx_kthread+0x10/0x10  ret_from_fork+0x576/0x810  ? __pfx_ret_from_fork+0x10/0x10  ? srso_alias_return_thunk+0x5/0xfbef5  ? __switch_to+0x57e/0xe10  ? __switch_to_asm+0x33/0x70  ? __pfx_kthread+0x10/0x10  ret_from_fork_asm+0x1a/0x30  \u003c/TASK\u003e  Allocated by task 970:  kasan_save_stack+0x33/0x60  kasan_save_track+0x14/0x30  __kasan_kmalloc+0xaa/0xb0  __kvmalloc_node_noprof+0x353/0x920  ntfs_rl_realloc+0x3c/0x80  ntfs_runlists_merge+0x1212/0x3010  ntfs_mft_data_extend_allocation_nolock+0x3e0/0x1f40  ntfs_mft_record_alloc+0x1ab4/0x4f10  __ntfs_create+0x680/0x2e50  ntfs_create+0x1e6/0x3a0  path_openat+0x2b55/0x3c10  do_file_open+0x1f4/0x460  do_sys_openat2+0xde/0x170  __x64_sys_openat+0x122/0x1e0  do_syscall_64+0x115/0x6a0  entry_SYSCALL_64_after_hwframe+0x77/0x7f  Freed by task 1294:  kasan_save_ ---truncated---","modified":"2026-09-14T17:03:31.102058349Z","published":"2026-08-15T06:22:08.840Z","upstream":["CVE-2026-72354"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-72354"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.5-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.107-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.10-1","6.16.11-1","6.16.12-1","6.16.12-1~bpo13+1","6.16.12-2","6.16.3-1","6.16.3-1~bpo13+1","6.16.5-1","6.16.6-1","6.16.7-1","6.16.8-1","6.16.9-1","6.16~rc7-1~exp1","6.17.10-1","6.17.11-1","6.17.12-1","6.17.13-1","6.17.13-1~bpo13+1","6.17.2-1~exp1","6.17.5-1~exp1","6.17.6-1","6.17.7-1","6.17.7-2","6.17.8-1","6.17.8-1~bpo13+1","6.17.9-1","6.18.1-1~exp1","6.18.10-1","6.18.12-1","6.18.12-1~bpo13+1","6.18.13-1","6.18.14-1","6.18.15-1","6.18.15-1~bpo13+1","6.18.2-1~exp1","6.18.3-1","6.18.5-1","6.18.5-1~bpo13+1","6.18.8-1","6.18.9-1","6.18.9-1~bpo13+1","6.18~rc4-1~exp1","6.18~rc4-1~exp2","6.18~rc5-1~exp1","6.18~rc6-1~exp1","6.18~rc7-1~exp1","6.19-1~exp1","6.19.10-1","6.19.10-1~bpo13+1","6.19.11-1","6.19.11-1~bpo13+1","6.19.12-1","6.19.13-1","6.19.13-1~bpo13+1","6.19.14-1","6.19.14-1~bpo13+1","6.19.2-1~exp1","6.19.3-1~exp1","6.19.4-1~exp1","6.19.5-1~exp1","6.19.6-1","6.19.6-2","6.19.6-2~bpo13+1","6.19.8-1","6.19.8-1~bpo13+1","6.19~rc4-1~exp1","6.19~rc5-1~exp1","6.19~rc6-1~exp1","6.19~rc7-1~exp1","6.19~rc8-1~exp1","7.0-1~exp1","7.0.1-1~exp1","7.0.10-1","7.0.10-1~bpo13+1","7.0.12-1","7.0.12-2","7.0.12-2~bpo13+1","7.0.13-1","7.0.13-1~bpo13+1","7.0.14-1","7.0.3-1","7.0.4-1","7.0.4-1~bpo13+1","7.0.7-1","7.0.7-1~bpo13+1","7.0.9-1","7.0.9-1~bpo13+1","7.1.1-1~exp1","7.1.2-1~exp1","7.1.3-1","7.1.3-1+sunvdc","7.1.3-1~bpo13+1","7.1.4-1","7.1~rc2-1~exp1","7.1~rc3-1~exp1","7.1~rc4-1~exp1","7.1~rc4-1~exp2","7.1~rc5-1~exp1","7.1~rc7-1~exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-72354.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}