PT-2025-44135 · Linux+3 · Linux Kernel+3

Published

2025-07-22

·

Updated

2026-05-07

·

CVE-2025-40067

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the NTFS3 file system driver. The issue arises when attempting index allocation if the $BITMAP attribute is empty, yet index blocks are present, indicating potential on-disk corruption. A malformed NTFS image, triggered by a syzbot, can cause this condition. Specifically, during a rename() operation with a long filename spanning multiple index entries, an empty bitmap allows the name to be added without proper tracking. Subsequent deletion of the original entry then fails. The issue was triggered by a rename() operation. The $BITMAP attribute is used to track the usage of index entries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Validation of Array Index

Weakness Enumeration

Related Identifiers

BDU:2025-13783
CVE-2025-40067
MGASA-2025-0309
MGASA-2025-0310
OPENSUSE-SU-2025:15702-1
OPENSUSE-SU-2026:10301-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Linuxmint
Linux Kernel
Ntfs3
Ubuntu