PatchSiren cyber security CVE debrief
CVE-2025-71266 Linux CVE debrief
CVE-2025-71266 is a Linux kernel ntfs3 vulnerability in directory lookup handling. A malformed dentry can drive indx_find() into a repeated loop over the same index block, and the missing return-value check on fnd_push() allows processing to continue when the node stack is exceeded. The result is repeated 4 KB allocations, memory exhaustion, and a local denial of service, including a hang or OOM crash. NVD classifies the issue as CVSS 5.5/Medium with low-privilege, local attack requirements and high availability impact.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-28
Who should care
Linux kernel and distro maintainers, operations teams, and system owners who run ntfs3 or mount untrusted NTFS volumes. It is especially relevant anywhere kernel availability matters and local users or mounted media can influence filesystem lookups.
Technical summary
NVD lists this as CWE-835 (infinite loop) affecting the Linux kernel ntfs3 filesystem. The issue is triggered during lookup operations on malformed directory data in INDEX_ALLOCATION blocks. The published fix is to check the return value of fnd_push() inside indx_find(); when the node array limit is reached, fnd_push() returns -EINVAL and indx_find() stops instead of continuing to allocate memory. NVD's affected-version ranges include: 5.15.1 through before 5.15.202; 5.16 through before 6.1.165; 6.2 through before 6.6.128; 6.7 through before 6.12.75; 6.13 through before 6.18.16; and 6.19 through before 6.19.6. The CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.
Defensive priority
Medium
Recommended defensive actions
- Apply the Linux kernel updates that contain the ntfs3 fix, or install your vendor's backported security update for the affected branch.
- Verify whether your systems use ntfs3 and prioritize patching those hosts if they mount untrusted NTFS media or depend on NTFS access.
- Track distro advisories for the affected kernel branches listed by NVD and confirm the fix is present in your shipped kernel build.
- If you cannot patch immediately, reduce exposure to untrusted NTFS content until an updated kernel is deployed.
- Validate remediation by confirming the patched kernel includes the stable backport commit references linked in NVD.
Evidence notes
All substantive claims are supported by the supplied CVE/NVD record and the linked Linux kernel stable patch references. The CVE description states the failure to check fnd_push() in indx_find() causes an infinite-loop DoS and memory exhaustion. NVD provides the CVSS vector, CWE-835 mapping, and affected-version ranges. The kernel.org stable references indicate the existence of vendor upstream/stable patches for remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-71266 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-71266
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-71266 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-71266
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0ad7a1be44479503dbe5c699759861ef5b8bd70c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/14c3188afbedfd5178bbabb8002487ea14b37b56
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1732053c8a6b360e2d5afb1b34fe9779398b072c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/398e768d1accd1f5645492ab996005d7aa84a5b0
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/435d34719db0e130f6f0c621d67ed524cc1a7d10
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/68e32694be231c1cdb99b7637a657314e88e1a96
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b0ea441f44ce64fa514a415d4a9e6e2b06e7946c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.