# CVE-2026-50472 — Windows LUA File Virtualization `luafv.sys` Racy FileId-Table Node Update in `UpdateTableNode` → Heap Buffer Overflow

---

## Summary

| | |
|---|---|
| **Product** | Windows — `luafv.sys` (LUA File Virtualization filter driver / LUAFV) |
| **CVE ID** | CVE-2026-50472 |
| **Impact** | Elevation of Privilege (to SYSTEM) |
| **MSRC severity** | Important |
| **CVSS** | 7.0 / 6.1 — `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C` |
| **CWE** | CWE-122: Heap-based Buffer Overflow (race-triggered) |
| **Delivery** | Local — concurrent LUAFV file-virtualization operations (race) |
| **KB / Fixed build** | KB5121003 — `luafv.sys` 10.0.26100.9168 (Win11 24H2 x64) |
| **Patch Date** | August 11, 2026 (2026-Aug) |
| **Pre-patch binary** | `luafv.sys` 10.0.26100.8972 — SHA256 `d0d5b2ebc6f13ade30cf326a11b4a5cdae61c4c8c69e22dc7becc5498a3e2560` |
| **Post-patch binary** | `luafv.sys` 10.0.26100.9168 — SHA256 `ad892825ec54bb5e431e5b1626a98767949c8ed86c50b752b9799ec520d3e96e` |
| **Feature flag** | `Feature_285200698` (also `Feature_3287483706` / `Feature_3614170424`) — **CFR-gated** |
| **Exploitability** | Exploitation Less Likely; not publicly disclosed; not exploited (per MSRC) |

---

## Product Description

`luafv.sys` (LUAFV) is the LUA File Virtualization minifilter that redirects/virtualizes
file access for legacy (non-elevated) applications. It maintains a table of **FileId
nodes** caching per-file state, including a path/name `UNICODE_STRING` stored at
node offset `+0x50`. `UpdateTableNode` refreshes a node from current file
information (`GetFileInformation`) and, on failure, removes the node
(`RemoveFileIdTableNode`).

---

## Vulnerability Summary

The FileId-table node update path was **insufficiently synchronized** against
concurrent update/removal of the same node. Under a race (`AC:H`), one thread could
update or reallocate a node's cached buffer while another path was still using the
node (or removing it), producing a heap buffer overflow of the node's allocation
(CWE-122). Because LUAFV runs in the kernel and its virtualization path is reachable
by a local user, winning the race yields a kernel heap corruption exploitable for
elevation to SYSTEM (per the MSRC FAQ).

> Confirmation: `UpdateTableNode` is confirmed code-changed under
> `Feature_285200698` with the hardening below; the exact overflowing write is not
> cleanly isolable in this race-hardening restructure, so the mechanism follows the
> CWE-122 + `AC:H` classification and the observed changes.

---

## Prerequisites and Constraints

- Local, low-privileged (`PR:L`, `AV:L`); `AC:H` — must win a race between concurrent
  operations on the same LUAFV FileId-table node.
- Drive LUAFV virtualization so `UpdateTableNode` runs concurrently with node
  update/removal.
- Result: the node's cached buffer is overflowed / corrupted.

---

## Vulnerability Details

### Root Cause

`UpdateTableNode`'s node refresh and `RemoveFileIdTableNode` removal were not
adequately serialized, so a concurrent update/reallocation could operate on a node
buffer another path held, overflowing the node allocation.

### The patch (confirmed — diff, .8972 → .9168)

Gated behind `Feature_285200698`, `UpdateTableNode` is hardened:

```c
// UpdateTableNode (10.0.26100.9168) — PATCHED, feature-enabled branch (from our diff)
// 1) verify the node still matches before acting on it:
local_140 = RtlCompareUnicodeString(&local_130, param_1 + 0x50, 1);   // name-match check
...
// 2) gate the node removal so it isn't removed out from under a concurrent update:
if (Feature_285200698__private_IsEnabledDeviceUsageNoInline())
    RemoveFileIdTableNode(param_1);
// 3) allocate the node buffer through the LUAFV wrapper instead of raw ExAllocatePool2:
//    UpdateTableNode now calls LuafvAllocatePool(...)
```

Adding the name-match check, gating the removal, and routing allocation through
`LuafvAllocatePool` prevents a racing update from operating on a node whose buffer
was reallocated/removed concurrently, closing the race-triggered overflow.

### Patch Completeness Assessment

**CFR-gated behind `Feature_285200698`.** The hardened update runs only when the flag
is enabled; the original path still ships when disabled. Verify `Feature_285200698`
is enabled to confirm the fix is live.

---

## Detection Guidance

**Behavioural.** Concurrent LUAFV file-virtualization operations that repeatedly
update/remove the same FileId node; heap-corruption bugchecks in
`luafv!UpdateTableNode` / `RemoveFileIdTableNode` on unpatched/flag-disabled builds.

**Config.** The fix is CFR-gated — confirm `Feature_285200698` is enabled.

---

## References

- MSRC advisory — CVE-2026-50472 (Windows LUAFV Elevation of Privilege), released 2026-08-11, KB5121003.
- Full binary diff: `/data/patch_diffs/luafv_sys-cve-2026-50472-ghidriff.md`
