Linux Kernel NTFS Volume Label Accesses Synchronization Vulnerability

Vulnerability

A use-after-free vulnerability has been addressed in the Linux kernel's NTFS file system handling. The issue arose because the volume label was not properly synchronized, allowing concurrent read and write operations to interfere with each other. Specifically, when the FS_IOC_SETFSLABEL command was used to change the volume label, the FS_IOC_GETTSLABEL command could simultaneously read the old label, leading to a use-after-free condition. This vulnerability affects the Linux kernel's stable releases.

Impact

Exploitation of this vulnerability could lead to a use-after-free condition, potentially allowing for memory corruption or other unintended behavior in the NTFS file system handling.

Added: Jul 19, 2026, 12:55 PM
Updated: Jul 19, 2026, 12:55 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.0
remediation
7.7
relevance
9.7
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.