Linux Kernel NTFS d_compare Blocking CVE-2026-43245
CVE-2026-43245 Published on May 6, 2026
ntfs: ->d_compare() must not block
In the Linux kernel, the following vulnerability has been resolved:
ntfs: ->d_compare() must not block
... so don't use __getname() there. Switch it (and ntfs_d_hash(), while
we are at it) to kmalloc(PATH_MAX, GFP_NOWAIT). Yes, ntfs_d_hash()
almost certainly can do with smaller allocations, but let ntfs folks
deal with that - keep the allocation size as-is for now.
Stop abusing names_cachep in ntfs, period - various uses of that thing
in there have nothing to do with pathnames; just use k[mz]alloc() and
be done with that. For now let's keep sizes as-in, but AFAICS none of
the users actually want PATH_MAX.
Products Associated with CVE-2026-43245
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version a3a956c78efaa202b1d75190136671cf6e87bfbe and below 02ecc0978c459fd90bb24b2a946dd16d43e68fe5 is affected.
- Version a3a956c78efaa202b1d75190136671cf6e87bfbe and below 1be7ca86ce1794d966fda5d82181bc978b150fbc is affected.
- Version a3a956c78efaa202b1d75190136671cf6e87bfbe and below 142c444a395f4d26055c8a4473e228bb86283f1e is affected.
- Version a3a956c78efaa202b1d75190136671cf6e87bfbe and below fb4b1f969ba01fa1d4088467a02fc1e5f0806710 is affected.
- Version a3a956c78efaa202b1d75190136671cf6e87bfbe and below ca2a04e84af79596e5cd9cfe697d5122ec39c8ce is affected.
- Version 6.2 is affected.
- Before 6.2 is unaffected.
- Version 6.6.141, <= 6.6.* is unaffected.
- Version 6.12.91, <= 6.12.* is unaffected.
- Version 6.18.16, <= 6.18.* is unaffected.
- Version 6.19.6, <= 6.19.* is unaffected.
- Version 7.0, <= * is unaffected.