LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2025-71265

linux · linux kernel

Published
CVSS5.5
Severitymedium
WeaknessCWE-835
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Description

In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata We found an infinite loop bug in the ntfs3 file system that can lead to a Denial-of-Service (DoS) condition. A malformed NTFS image can cause an infinite loop when an attribute header indicates an empty run list, while directory entries reference it as containing actual data. In NTFS, setting evcn=-1 with svcn=0 is a valid way to represent an empty run list, and run_unpack() correctly handles this by checking if evcn + 1 equals svcn and returning early without parsing any run data. However, this creates a problem when there is metadata inconsist

References

← Back to the CVE Tracker

Our coverage of CVE-2025-71265

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-71265.