Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2025-71289

 

Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2025-71289

Published: May 7, 2026


Vulnerability identifier: #VU130619
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-71289
CWE-ID: CWE-703
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper error handling in attr_set_size() during file truncation when truncating files on ntfs3. A local user can truncate a file in a way that triggers an attr_set_size() failure to cause a denial of service.

The inode may be left in an inconsistent state if the error is ignored.


Affected software

Linux kernel
Debian Linux
Ubuntu
linux (Ubuntu package)
linux (Debian package)

How to mitigate CVE-2025-71289

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 6.8.0-139.139+fips1, 6.8.0-1049.53, 6.8.0-1062.65+fips1, 6.8.0-1062.65.1, 6.8.0-1062.65~22.04.1, 6.8.0-1062.70, 6.8.0-1064.68, 6.8.0-1067.75, 6.8.0-1067.75+fips1, 6.8.1-1059.60, 6.8.1-1059.60~22.04.1
linux (Debian package) - update to 6.12.94-1

External References

Related Security Bulletins