cbcvebase.
CVE-2025-40313
published 2025-12-08

CVE-2025-40313: In the Linux kernel, the following vulnerability has been resolved: ntfs3: pretend $Extend records as regular files Since commit af153bb63a33 ("vfs: catch…

PriorityP420high7.8
EPSS
0.19%
8.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ntfs3: pretend $Extend records as regular files Since commit af153bb63a33 ("vfs: catch invalid modes in may_open()") requires any inode be one of S_IFDIR/S_IFLNK/S_IFREG/S_IFCHR/S_IFBLK/ S_IFIFO/S_IFSOCK type, use S_IFREG for $Extend records.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e < 63eb6730ce0604d3eacf036c2f68ea70b068317c63eb6730ce0604d3eacf036c2f68ea70b068317c
linuxlinux>= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e < 78d46f5276ed3589aaaa435580068c5b62efc92178d46f5276ed3589aaaa435580068c5b62efc921
linuxlinux>= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e < 17249b2a65274f73ed68bcd1604e08a60fd8a27817249b2a65274f73ed68bcd1604e08a60fd8a278
linuxlinux>= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e < 37f65e68ba9852dc51c78dbb54a9881c3f0fe4f737f65e68ba9852dc51c78dbb54a9881c3f0fe4f7
linuxlinux>= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e < 57534db1bbc4ca772393bb7d92e69d5e7b9051cf57534db1bbc4ca772393bb7d92e69d5e7b9051cf
linuxlinux>= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e < 4e8011ffec79717e5fdac43a7e79faf811a384b74e8011ffec79717e5fdac43a7e79faf811a384b7
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.15.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-azure-5.15
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.