CVE-2025-40067

HIGHCVSS 7.8/10EPSS 0.19%

Last modified

CVE-2025-40067 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject index allocation if $BITMAP is empty but blocks exist Index allocation requires at least one bit in the $BITMAP attribute to track usage of index entries. If the bitmap is empty while index blocks are already present, this reflects on-disk corruption. syzbot triggered this condition using a malformed NTFS image. EPSS estimates a 0.19% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject index allocation if $BITMAP is empty but blocks exist Index allocation requires at least one bit in the $BITMAP attribute to track usage of index entries. If the bitmap is empty while index blocks are already present, this reflects on-disk corruption. syzbot triggered this condition using a malformed NTFS image. During a rename() operation involving a long filename (which spans multiple index entries), the empty bitmap allowed the name to be added without valid tracking. Subsequent deletion of the original entry failed with -ENOENT, due to unexpected index state. Reject such cases by verifying that the bitmap is not empty when index blocks exist.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
0.19%

8.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= b35a50d639ca5259466ef5fea85529bb4fb17d5b, < 978aac54e93ea35aab20b32ae393d3d33964e7ae; >= 3ed2cc6a6e93fbeb8c0cafce1e7fb1f64a331dcc, < be66551da203862c689c12e1d35ce87217c017c1; >= d99208b91933fd2a58ed9ed321af07dacd06ddc3, < 039ddf353cc33f6546a87ec1ac3210637d714bec; >= d99208b91933fd2a58ed9ed321af07dacd06ddc3, < 0dc7117da8f92dd5fe077d712a756eccbe377d40; 358d4f821c03add421a4c49290538a705852ccf1; a285395020780adac1ffbc844069c3d700bf007a; >= 6.6.102, < 6.6.112; >= 6.12.42, < 6.12.53; >= 6.15.10, < 6.16; >= 6.16.1, < 6.17
LinuxLinux6.17

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2025-40067?
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject index allocation if $BITMAP is empty but blocks exist Index allocation requires at least one bit in the $BITMAP attribute to track usage of index entries. If the bitmap is empty while index blocks are already present, this reflects on-disk corruption. syzbot triggered this condition using a malformed NTFS image. During a rename() operation involving a long filename (which spans multiple index entries), the empty bitmap allowed the name to be added without valid tracking. Subsequent deletion of the original entry failed with -ENOENT, due to unexpected index state. Reject such cases by verifying that the bitmap is not empty when index blocks exist.
How severe is CVE-2025-40067?
CVE-2025-40067 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.19% probability of exploitation in the next 30 days.
How do I fix CVE-2025-40067?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-40067?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST