CVE-2025-40287 — Numeric Range Comparison Without Minimum Check in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 90.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 6
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
exfat: fix improper check of dentry.stream.valid_size
We found an infinite loop bug in the exFAT file system that can lead to a
Denial-of-Service (DoS) condition. When a dentry in an exFAT filesystem is
malformed, the following system calls — SYS_openat, SYS_ftruncate, and
SYS_pwrite64 — can cause the kernel to hang.
Root cause analysis shows that the size validation code in exfat_find()
does not check whether dentry.stream.v…
Affected Packages6 packages
▶CVEListV5linux/linux11a347fb6cef62ce47e84b97c45f2b2497c7593b — 6c627bcc1896ba62ec793d0c00da74f3c93ce3ad+3