CVE-2025-71289: fs/ntfs3: handle attr_set_size() errors when truncating files
Published May 6, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: handle attrsetsize() errors when truncating files
If attrsetsize() fails while truncating down, the error is silently ignored and the inode may be left in an inconsistent state.
Affected Software
2 affected components
Linux Linux kernel (ntfs3)
Linux Linux kernel>=5.15<6.19.6
Event History
May 6, 2026
CVE Published
via MITRE·11:32 AM
Data Sourced
via MITRE·11:32 AM
DescriptionSeverity
Data Sourced
via NVD·12:16 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-71289?
CVE-2025-71289 is rated as a medium severity vulnerability.
2
How do I fix CVE-2025-71289?
To fix CVE-2025-71289, update your Linux kernel to the latest version where the vulnerability has been addressed.
3
What systems are affected by CVE-2025-71289?
CVE-2025-71289 affects the Linux kernel implementation for NTFS3.
4
What are the potential consequences of CVE-2025-71289?
The consequences of CVE-2025-71289 include the risk of data corruption or loss if errors during file truncation are not handled properly.
5
Is CVE-2025-71289 actively being exploited?
As of now, there are no public reports indicating that CVE-2025-71289 is actively being exploited in the wild.