Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-72189

Published Aug 15, 2026 EPSS 0.19% (9th pctl)

Overview

CVE-2026-72189 is a known-severity vulnerability. It was published on August 15, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ntfs: fail attrlist updates when the superblock is inactive

generic_shutdown_super() clears SB_ACTIVE before evicting cached inodes.

If eviction selects the fake inode for a base inode's unnamed

$ATTRIBUTE_LIST attribute, ntfs_evict_big_inode() drops the fake inode's

reference on the base inode while the fake inode is still hashed and marked

I_FREEING.

That iput can synchronously write back the base inode. The writeback path

may update mapping pairs and call ntfs_attrlist_update(), which

unconditionally calls ntfs_attr_iget() for the same $ATTRIBUTE_LIST fake

inode. VFS then finds the I_FREEING inode and waits for eviction to finish,

but the current task is still inside that eviction path, causing a

self-deadlock in find_inode().

Fix this by mirroring the teardown guard used by __ntfs_write_inode():

once SB_ACTIVE has been cleared, do not try to iget the attribute-list

fake inode. Return -EIO so teardown aborts the

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-72189?

CVE-2026-72189 is a known-severity vulnerability. It was published on August 15, 2026.

How severe is CVE-2026-72189?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-72189?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-72189?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-72189 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.