SB20251208130 - Input validation error in Linux kernel ntfs3
Published: December 8, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2025-40313)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the ntfs_read_mft() function in fs/ntfs3/inode.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/17249b2a65274f73ed68bcd1604e08a60fd8a278
- https://git.kernel.org/stable/c/37f65e68ba9852dc51c78dbb54a9881c3f0fe4f7
- https://git.kernel.org/stable/c/4e8011ffec79717e5fdac43a7e79faf811a384b7
- https://git.kernel.org/stable/c/57534db1bbc4ca772393bb7d92e69d5e7b9051cf
- https://git.kernel.org/stable/c/63eb6730ce0604d3eacf036c2f68ea70b068317c
- https://git.kernel.org/stable/c/78d46f5276ed3589aaaa435580068c5b62efc921