Junglewise Threat Intelligence

CVE-2025-38615: Linux Kernel ntfs3 improper inode management in ni_rename

CVE-2025-38615 · Severity: high · CVSS 7.8 · Published 2025-08-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's NTFS3 file system driver, which is used to read and write Windows-formatted drives. A local user could potentially trigger a system crash or instability by performing file rename operations on a specially crafted or corrupted NTFS volume. This issue stems from the system incorrectly marking active files as 'bad' during certain error conditions, leading to memory management conflicts.

Technical details

A vulnerability exists in the fs/ntfs3 component of the Linux kernel due to the improper use of make_bad_inode() on live inodes. When renaming a file on an NTFS3 filesystem with a corrupted i_link, the driver may attempt to mark an active inode as bad if name removal fails. This can lead to race conditions where one thread evicts an inode from the icache while another thread is still using it (e.g., via d_splice_alias). The issue is triggered locally during rename operations. Patches have been released for multiple stable kernel branches including 6.16.1, 6.15.10, 6.12.42, and 6.6.102.

Affected products

  • Linux Linux Kernel 5.15 to 6.6.102, 6.7 to 6.12.42, 6.13 to 6.15.10, 6.16 to 6.16.1

Timeline

  • 2025-08-15: patched: Fixes committed to stable kernel trees.
  • 2025-08-19: disclosed: CVE published.

References

Related threats