CVE-2026-63793

HIGH

ntfs: serialize volume label accesses

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ntfs: serialize volume label accesses Protect vol->volume_label with a mutex and snaphost the label before copy_to_user. This prevent a use-after-free when FS_IOC_SETFSLABEL replaces the vol->volume_label and FS_IOC_GETTSLABEL reads it concurrently.

Scores

CVSS v3 7.8
EPSS 0.0012
EPSS Percentile 2.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (12)
linux/Kernel < 7.1.3linux
linux/Kernel 7.1.0 - 7.1.3linux
Linux/Linux < 7.1
Linux/Linux < 7.1.3
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - acd744019460bad22e43d4569a502f9c88d331ae
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - e9e50ce4f13dc721014af622613409455c734942
Linux/Linux 7.1
Linux/Linux 7.1.3 - 7.1.*
Linux/Linux 7.2-rc1
Linux/Linux 9c87959601e80b39a45250e362e6ddfec17cb0fa - acd744019460bad22e43d4569a502f9c88d331ae
... and 2 more
Published Jul 19, 2026
Tracked Since Jul 19, 2026