Vulnerability Details CVE-2026-63793
In the Linux kernel, the following vulnerability has been resolved:
ntfs: serialize volume label accesses
Protect vol->volume_label with a mutex and snaphost the label before
copy_to_user. This prevent a use-after-free when FS_IOC_SETFSLABEL
replaces the vol->volume_label and FS_IOC_GETTSLABEL reads it
concurrently.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 2.3%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2026-63793
-
cpe:2.3:o:linux:linux_kernel:7.1
-
cpe:2.3:o:linux:linux_kernel:7.1.1
-
cpe:2.3:o:linux:linux_kernel:7.1.2