CVE-2025-40067 — Linux vulnerability
32 documents6 sources
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 92.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 28
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: reject index allocation if $BITMAP is empty but blocks exist
Index allocation requires at least one bit in the $BITMAP attribute to
track usage of index entries. If the bitmap is empty while index blocks
are already present, this reflects on-disk corruption.
syzbot triggered this condition using a malformed NTFS image. During a
rename() operation involving a long filename (which spans multiple
index entries), the em…
Affected Packages5 packages
▶CVEListV5linux/linuxb35a50d639ca5259466ef5fea85529bb4fb17d5b — 978aac54e93ea35aab20b32ae393d3d33964e7ae+6