CVE-2025-71289: fs/ntfs3: handle attr_set_size() errors when truncating files
Published May 6, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
3 affected componentsFixes available
Linux Linux kernel (ntfs3)
Linux Linux kernel>=5.15<6.19.6
debian/linux<=6.1.176-1, <=6.1.187-1
6.12.107-17.2.6-17.2.7-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.107-1Fixed in 7.2.6-1Fixed in 7.2.7-1
Event History
May 6, 2026
CVE Published
via MITRE·11:32 AM
Data Sourced
via MITRE·11:32 AM
DescriptionSeverity
Data Sourced
via NVD·12:16 PM
RemedyDescriptionSeverityAffected Software
Sep 22, 2026
Data Sourced
via Launchpad·02:53 PM
Description
Sep 24, 2026
Data Sourced
via Ubuntu·02:55 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·02:56 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-71289?
CVE-2025-71289 is rated as a medium severity vulnerability.
2
How do I fix CVE-2025-71289?
To fix CVE-2025-71289, update your Linux kernel to the latest version where the vulnerability has been addressed.
3
What systems are affected by CVE-2025-71289?
CVE-2025-71289 affects the Linux kernel implementation for NTFS3.
4
What are the potential consequences of CVE-2025-71289?
The consequences of CVE-2025-71289 include the risk of data corruption or loss if errors during file truncation are not handled properly.
5
Is CVE-2025-71289 actively being exploited?
As of now, there are no public reports indicating that CVE-2025-71289 is actively being exploited in the wild.