Executive brief
A vulnerability was identified in the Linux kernel's NTFS3 file system driver, which is used to read and write Windows-formatted drives. A local attacker could potentially exploit this flaw to cause a system crash or gain unauthorized access to sensitive information. The issue stems from a lack of proper validation when processing file names within directory entries.
Technical details
A vulnerability exists in the fs/ntfs3/dir.c component of the Linux kernel. The ntfs_dir_emit function failed to validate that a file name's length was smaller than the directory entry size (NTFS_DE). A local attacker with low privileges could exploit this lack of sanity checking to trigger out-of-bounds memory access. This can result in a denial of service (system crash) or information disclosure. The issue has been addressed by adding a check to ensure fname->name_len + sizeof(struct NTFS_DE) does not exceed the entry size. Patches have been backported to multiple stable kernel branches including 5.15.y, 6.1.y, 6.6.y, and 6.12.y.
Affected products
- Linux Linux Kernel 5.15 to 6.16.2
- Siemens SIMATIC CN 4100 before V5.0
Timeline
- 2025-06-06: patched: Initial patch authored by Lizhi Xu
- 2025-09-04: disclosed: CVE published to NVD
References
- https://git.kernel.org/stable/c/27ee9a42b245efe6529e28b03453291a775cb3e4
- https://git.kernel.org/stable/c/2ac47f738ddfc1957a33be163bc97ee8f78e85a6
- https://git.kernel.org/stable/c/3572737a768dadea904ebc4eb34b6ed575bb72d9
- https://git.kernel.org/stable/c/b51642fc52d1c7243a9361555d5c4b24d7569d7e
- https://git.kernel.org/stable/c/bde58c1539f3ffddffc94d64007de16964e6b8eb
- https://git.kernel.org/stable/c/e841ecb139339602bc1853f5f09daa5d1ea920a2
- https://git.kernel.org/stable/c/f99eb9a641f4ef927d8724f4966dcfd1f0e9f835