CVE-2026-72478
Linux ntfs3 parsing bug causes out-of-bounds read during mount
Is CVE-2026-72478 being exploited?
Not confirmed. CVE-2026-72478 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.15% probability of exploitation in the next 30 days.
How severe is CVE-2026-72478?
CVE-2026-72478 is rated High with a CVSS score of 8.4. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72478?
Yes. A fix has been recorded for CVE-2026-72478. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72478 affect?
CVE-2026-72478 affects Linux kernel (ntfs3 filesystem driver). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72478?
Install kernel/security update; avoid mounting untrusted NTFS images.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Out-of-bounds read in ntfs3 during mount; can crash the kernel (DoS) and may disclose kernel memory.
Patch when possible
- affected>= 425de2aba0d061b3e715d51a3b1992c112ed5b99 and < c69b9003332917b652175d5fa9d84158c5ed8617
- affected>= bf7ac4a1d3bfc6e56e54635c3d331a68170d37c9 and < 8afc24a884aff6a6f08028bd779ee65c40054455
- affected>= e64f7dfcaff79e7dfff9121a382dd77f9b462f62 and < c23083b472a720c3f60b147db05b25b751c7c1bf
- affected>= d3012690a7065d9ca86521a525ad11e8af491d45 and < a31893206588374d7d16fad387189d8165c7efd3
- affected>= b62567bca47408e6739dee75f02a2113548af875 and < 41081202eb823f5b27ff164b12010b24428100ad
- affected>= b62567bca47408e6739dee75f02a2113548af875 and < bb11485a87fbb2254b62cfed630b699d50e57da8
- affectedbbad75336870b51b81979b97613746237fcb02fe
- affected41aadf5cb482793a24e05aa136224e179a778586
- affected>= 6.1.175 and < 6.1.178
- affected>= 6.6.140 and < 6.6.145
- affected>= 6.12.86 and < 6.12.97
- affected>= 6.18.27 and < 6.18.40
- affected>= 5.15.209 and < 5.16
- affected>= 7.0.4 and < 7.1
- affected7.1
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.