CVE-2026-63793

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
19/07/2026
Last modified:
17/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ntfs: serialize volume label accesses<br /> <br /> Protect vol-&gt;volume_label with a mutex and snaphost the label before<br /> copy_to_user. This prevent a use-after-free when FS_IOC_SETFSLABEL<br /> replaces the vol-&gt;volume_label and FS_IOC_GETTSLABEL reads it<br /> concurrently.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 7.1 (including) 7.1.3 (excluding)