Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2025-71289
Published: May 7, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper error handling in attr_set_size() during file truncation when truncating files on ntfs3. A local user can truncate a file in a way that triggers an attr_set_size() failure to cause a denial of service.
The inode may be left in an inconsistent state if the error is ignored.
Affected software
Debian Linux
Ubuntu
linux (Ubuntu package)
linux (Debian package)
How to mitigate CVE-2025-71289
linux (Ubuntu package) - addressed in versions 6.8.0-139.139+fips1, 6.8.0-1049.53, 6.8.0-1062.65+fips1, 6.8.0-1062.65.1, 6.8.0-1062.65~22.04.1, 6.8.0-1062.70, 6.8.0-1064.68, 6.8.0-1067.75, 6.8.0-1067.75+fips1, 6.8.1-1059.60, 6.8.1-1059.60~22.04.1
linux (Debian package) - update to 6.12.94-1