PT-2025-52905 · Linux+4 · Linux Kernel+4

Syzbot

·

Published

2025-11-10

·

Updated

2026-05-11

·

CVE-2025-68369

CVSS v2.0

4.0

Medium

VectorAV:A/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to the NTFS3 file system. Specifically, an uninitialized run lock error can occur when handling the $Extend inode after setting its mode to a regular file and then executing a truncate system call. This issue arises because the run lock is not initialized when loading $Extend. The problem was reported by syzbot and addressed by initializing the run lock during the loading of $Extend.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Initialization

Weakness Enumeration

Related Identifiers

BDU:2026-01309
CVE-2025-68369
MGASA-2026-0017
MGASA-2026-0018
OPENSUSE-SU-2026:10039-1
OPENSUSE-SU-2026:10301-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8152-1
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8258-1
USN-8260-1
USN-8265-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ntfs3
Ubuntu