Junglewise Threat Intelligence

CVE-2025-38707: Linux Kernel ntfs3 missing sanity check in directory entry parsing

CVE-2025-38707 · Severity: high · CVSS 7.1 · Published 2025-09-04

Technologies: Siemens SIMATIC CN 4100, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability was identified in the Linux kernel's NTFS3 file system driver, which is used to read and write Windows-formatted drives. A local attacker could potentially exploit this flaw to cause a system crash or gain unauthorized access to sensitive information. The issue stems from a lack of proper validation when processing file names within directory entries.

Technical details

A vulnerability exists in the fs/ntfs3/dir.c component of the Linux kernel. The ntfs_dir_emit function failed to validate that a file name's length was smaller than the directory entry size (NTFS_DE). A local attacker with low privileges could exploit this lack of sanity checking to trigger out-of-bounds memory access. This can result in a denial of service (system crash) or information disclosure. The issue has been addressed by adding a check to ensure fname->name_len + sizeof(struct NTFS_DE) does not exceed the entry size. Patches have been backported to multiple stable kernel branches including 5.15.y, 6.1.y, 6.6.y, and 6.12.y.

Affected products

  • Linux Linux Kernel 5.15 to 6.16.2
  • Siemens SIMATIC CN 4100 before V5.0

Timeline

  • 2025-06-06: patched: Initial patch authored by Lizhi Xu
  • 2025-09-04: disclosed: CVE published to NVD

References

Related threats