Junglewise Threat Intelligence

CVE-2025-71309: Linux Kernel ntfs3 deadlock in ni_read_folio_cmpr

CVE-2025-71309 · Severity: info · CVSS 4.7 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's NTFS3 file system driver can cause the system to hang or become unresponsive. This occurs when the system attempts to read compressed files, leading to a 'deadlock' where two internal processes wait for each other indefinitely. This primarily impacts system availability and could be used to cause a denial-of-service on affected machines.

Technical details

A lock inversion deadlock was identified in the fs/ntfs3 driver within the ni_read_folio_cmpr function. The issue arises because the driver previously acquired the inode mutex (ni_lock) before attempting to lock pages in a compressed frame. If a concurrent task (such as readahead) already held a page lock and then attempted to acquire the same inode mutex, a circular dependency occurred. The fix restructures the locking order to ensure all required page locks are acquired before the inode mutex is taken, aligning with standard VFS locking conventions. This vulnerability is reachable by local users interacting with compressed NTFS volumes.

Affected products

  • Linux Linux Kernel versions using ntfs3 driver with compressed I/O support

Timeline

  • 2025-12-22: other: Patch authored
  • 2026-02-26: patched: Patch committed to stable tree
  • 2026-05-27: advisory: NVD publication date

References

Related threats