cbcvebase.
CVE-2025-40067
published 2025-10-28

CVE-2025-40067: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject index allocation if $BITMAP is empty but blocks exist Index allocation…

PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.15%
5.1th percentile
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject index allocation if $BITMAP is empty but blocks exist Index allocation requires at least one bit in the $BITMAP attribute to track usage of index entries. If the bitmap is empty while index blocks are already present, this reflects on-disk corruption. syzbot triggered this condition using a malformed NTFS image. During a rename() operation involving a long filename (which spans multiple index entries), the empty bitmap allowed the name to be added without valid tracking. Subsequent deletion of the original entry failed with -ENOENT, due to unexpected index state. Reject such cases by verifying that the bitmap is not empty when index blocks exist.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.6-1 (forky)linux 6.17.6-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3ed2cc6a6e93fbeb8c0cafce1e7fb1f64a331dcc < be66551da203862c689c12e1d35ce87217c017c1be66551da203862c689c12e1d35ce87217c017c1
linuxlinux>= 6.12.42 < 6.12.536.12.53
linuxlinux>= 6.15.10 < 6.166.16
linuxlinux>= 6.16.1 < 6.176.17
linuxlinux>= 6.6.102 < 6.6.1126.6.112
linuxlinux>= b35a50d639ca5259466ef5fea85529bb4fb17d5b < 978aac54e93ea35aab20b32ae393d3d33964e7ae978aac54e93ea35aab20b32ae393d3d33964e7ae
linuxlinux>= d99208b91933fd2a58ed9ed321af07dacd06ddc3 < 039ddf353cc33f6546a87ec1ac3210637d714bec039ddf353cc33f6546a87ec1ac3210637d714bec
linuxlinux>= d99208b91933fd2a58ed9ed321af07dacd06ddc3 < 0dc7117da8f92dd5fe077d712a756eccbe377d400dc7117da8f92dd5fe077d712a756eccbe377d40
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.6.1126.6.112
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.13.0 < 6.17.36.17.3
linuxlinux_kernel>= 6.7.0 < 6.12.536.12.53
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv3.2LOW
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.