PatchSiren cyber security CVE debrief
CVE-2025-71265 Linux CVE debrief
CVE-2025-71265 is a Linux kernel ntfs3 flaw that can lead to a denial of service when malformed NTFS metadata is encountered. According to the NVD record, the issue is a local vulnerability with low attack complexity and low privileges required, and it affects multiple Linux kernel release branches. The kernel fix referenced by NVD prevents attr_load_runs_range() from spinning forever when run_lookup_entry() repeatedly fails after an inconsistent empty-run-list condition.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-28
Who should care
Linux kernel maintainers, distro security teams, fleet operators, and administrators who mount or process untrusted NTFS volumes or images should prioritize this issue. Environments that use ntfs3 and may encounter user-supplied or external NTFS media are the most relevant.
Technical summary
The supplied description says a malformed NTFS image can present inconsistent metadata: the attribute header can indicate an empty run list (evcn=-1 with svcn=0), while the caller expects actual data. run_unpack() correctly returns early for the empty-run-list case, but if the surrounding metadata is inconsistent, runs_tree remains uninitialized and attr_load_runs_range() can keep calling run_lookup_entry() without making progress. Because vcn is incremented by zero in that failure path, the loop does not terminate. The patch adds a retry counter and returns -EINVAL after repeated lookup failure, which stops the infinite loop and prevents the DoS condition.
Defensive priority
Medium. This is a local denial-of-service issue in a kernel filesystem path, so it does not indicate direct remote code execution, but it can still hang or degrade systems that process untrusted NTFS content.
Recommended defensive actions
- Upgrade to a Linux kernel version that includes the ntfs3 fix or verify that your distribution has backported it.
- Check whether your fleet is exposed to untrusted NTFS media, disk images, or removable storage and prioritize patching those systems.
- Confirm remediation against the NVD-listed fixed branches and end versions: 5.15.202, 6.1.165, 6.6.128, 6.12.75, 6.18.16, and 6.19.6.
- Track vendor advisories and kernel stable backports for your specific distro kernel rather than relying only on upstream version numbers.
- If patching must be delayed, reduce exposure to untrusted NTFS content on systems that rely on ntfs3.
Evidence notes
Evidence is drawn from the supplied NVD record and its official references. NVD marks the vulnerability as Analyzed and classifies it with CVSS 3.1 vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, with CWE-835 listed as the primary weakness. NVD also lists affected Linux kernel ranges for 5.15, 5.16, 6.2, 6.7, 6.13, and 6.19 branches, each with an upper bound indicating the fixed release threshold. The supplied description explains the infinite-loop mechanism and the retry-counter mitigation. The official patch references from git.kernel.org are the primary remediation evidence.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-71265 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-71265
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-71265 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-71265
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3c3a6e951b9b53dab2ac460a655313cf04c4a10a
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4b90f16e4bb5607fb35e7802eb67874038da4640
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6f07a590616ff5f57f7c041d98e463fad9e9f763
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/78b61f7eac37a63284774b147f38dd0be6cad43c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a89bc96d5abd8a4a8d5d911884ea347efcdf460b
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/af839013c70a24779f9d1afb1575952009312d38
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c0b43c45d45f59e7faad48675a50231a210c379b
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.