CVE-2025-71267

MEDIUM EPSS 2.0%
Published Mar 18, 20263mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Mar 18, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop triggered by zero-sized ATTR_LIST We found an infinite loop bug in the ntfs3 file system that can lead to a Denial-of-Service (DoS) condition. A malformed NTFS image can cause an infinite loop when an ATTR_LIST attribute indicates a zero data size while the driver allocates memory for it. When ntfs_load_attr_list() processes a resident ATTR_LIST with data_size set to zero, it still allocates memory because of al_aligned(0). This creates an inconsistent state where ni->attr_list.size is zero, but ni->attr_list.le is non-null. This causes ni_enum_attr_ex to incorrectly assume that no attribute list exists and enumerates only the primary MFT record. When it finds ATTR_LIST, the code reloads it and restarts the enumeration, repeating indefinitely. The mount operation never completes, hanging the kernel thread. This patch adds validation to ensure that data_size is non-zero before memory allocation. When a zero-sized ATTR_LIST is detected, the function returns -EINVAL, preventing a DoS vulnerability.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.0% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-835

Affected Products 6

VendorProductVersionRange
linuxlinux_kernel*≥5.15  –  <5.15.202
linuxlinux_kernel*≥5.16  –  <6.1.165
linuxlinux_kernel*≥6.2  –  <6.6.128
linuxlinux_kernel*≥6.7  –  <6.12.75
linuxlinux_kernel*≥6.13  –  <6.18.16
linuxlinux_kernel*≥6.19  –  <6.19.6

References 7

  • git.kernel.org https://git.kernel.org/stable/c/06909b2549d631a47fcda249d34be26f7ca1711d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7ef219656febf5ae06ae56b1fce47ebd05f92b68
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8d8c70b57dbeda3eb165c0940b97e85373ca9354
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9267d99fade76d44d4a133599524031fe684156e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/976e6a7c51fabf150478decbe8ef5d9a26039b7c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9779a6eaaabdf47aa57910d352b398ad742e6a5f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fd508939dbca5eceefb2d0c2564beb15469572f2
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/06909b2549d631a47fcda249d34be26f7ca1711d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7ef219656febf5ae06ae56b1fce47ebd05f92b68
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8d8c70b57dbeda3eb165c0940b97e85373ca9354
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9267d99fade76d44d4a133599524031fe684156e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/976e6a7c51fabf150478decbe8ef5d9a26039b7c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9779a6eaaabdf47aa57910d352b398ad742e6a5f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fd508939dbca5eceefb2d0c2564beb15469572f2
    Patch