{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.180-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.5-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  fs/ntfs3: bound DeleteIndexEntryAllocation memmove length  In do_action()'s DeleteIndexEntryAllocation case, e-\u003esize comes from an on-disk INDEX_BUFFER entry.  When e-\u003esize makes e + e-\u003esize point past hdr + hdr-\u003eused, PtrOffset(e1, Add2Ptr(hdr, used)) returns a negative ptrdiff_t that is silently cast to a quasi-infinite size_t when passed to memmove().  The memmove then walks past the destination buffer.  The sibling DeleteIndexEntryRoot case at fslog.c:3540-3543 already carries the corresponding guard:  \tif (PtrOffset(e1, Add2Ptr(hdr, used)) \u003c esize || \t    Add2Ptr(e, esize) \u003e Add2Ptr(lrh, rec_len) || \t    used + esize \u003e le32_to_cpu(hdr-\u003etotal)) { \t\tgoto dirty_vol; \t}  Apply the same shape to the allocation-path case.  Also reject esize == 0: memmove(e, e, ...) is a no-op and leaves hdr-\u003eused unchanged, hiding a malformed entry from the existing check_index_header() walk.  Reproduced under UML+KASAN on mainline 8d90b09e6741 by mounting a crafted NTFS image: the unguarded memmove takes a length of 0xffffffffffffff00 and the kernel oopses in memmove+0x81/0x1a0 on the do_action+0x36a2 frame.  [almaz.alexandrovich@paragon-software.com: clang-formatted the changes]",
  "id": "DEBIAN-CVE-2026-72197",
  "modified": "2026-09-14T16:47:45.906326294Z",
  "published": "2026-08-15T06:21:38.323Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-72197"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-72197"
  ]
}