CVE-2025-71265: fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata

Published Mar 18, 2026
·
Updated

fs: ntfs3: fix infinite loop in attrloadrunsrange on inconsistent metadata

Affected Software

8 affected componentsFixes available
The Linux Foundation Linux Kernel
Microsoft azl3 kernel 6.6.126.1-1
Linux Linux kernel>=5.15<5.15.202
Linux Linux kernel>=5.16<6.1.165
Linux Linux kernel>=6.2<6.6.128
Linux Linux kernel>=6.7<6.12.75
Linux Linux kernel>=6.13<6.18.16
Linux Linux kernel>=6.19<6.19.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Linux kernel (ntfs3) to a version that resolves this vulnerability.

    Fixed in resolvedPatch fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata
  2. Configuration

    Apply the ntfs3 patch that adds a retry counter so attr_load_runs_range() detects repeated run_lookup_entry() failures and prevents the infinite loop on inconsistent metadata.

    Linux kernel ntfs3 retry counter for run_lookup_entry() failures = enabled
  3. Compensating control

    Mitigate DoS impact by restricting access/usage of NTFS3 volumes until the patched kernel is deployed.

Event History

Mar 18, 2026
CVE Published
via MITRE·10:05 AM
Data Sourced
via MITRE·10:05 AM
Description
Data Sourced
via NVD·11:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 19, 2026
Data Sourced
via Microsoft·08:04 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:04 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2025-71265?

CVE-2025-71265 has been classified as a moderate severity vulnerability due to the potential for causing an infinite loop in the ntfs3 file system.

2

How do I fix CVE-2025-71265?

To fix CVE-2025-71265, you should update your Linux kernel to the latest patched version that addresses this vulnerability.

3

What systems are affected by CVE-2025-71265?

CVE-2025-71265 affects the ntfs3 file system implemented in the Linux kernel.

4

Can CVE-2025-71265 cause data loss?

CVE-2025-71265 can potentially lead to system instability, and while it doesn't directly cause data loss, it can interfere with file system operations.

5

Is CVE-2025-71265 exploited in the wild?

As of now, there have been no reported exploits of CVE-2025-71265 in the wild, but it is advisable to apply the update to prevent potential risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203