{"id":"CVE-2025-71266","title":"fs: ntfs3: check return value of indx_find to avoid infinite loop","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs: ntfs3: check return value of indx_find to avoid infinite loop\n\nWe found an infinite loop bug in the ntfs3 file system that can lead to a\nDenial-of-Service (DoS) con…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < 14c3188afbedfd5178bbabb8002487ea14b37b56","Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < 435d34719db0e130f6f0c621d67ed524cc1a7d10","Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < 68e32694be231c1cdb99b7637a657314e88e1a96","Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < 398e768d1accd1f5645492ab996005d7aa84a5b0","Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < b0ea441f44ce64fa514a415d4a9e6e2b06e7946c","Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < 0ad7a1be44479503dbe5c699759861ef5b8bd70c","Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < 1732053c8a6b360e2d5afb1b34fe9779398b072c","Linux 5.15"],"published":"2026-03-18","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:44:19.375Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-71266","references":[{"url":"https://git.kernel.org/stable/c/14c3188afbedfd5178bbabb8002487ea14b37b56"},{"url":"https://git.kernel.org/stable/c/435d34719db0e130f6f0c621d67ed524cc1a7d10"},{"url":"https://git.kernel.org/stable/c/68e32694be231c1cdb99b7637a657314e88e1a96"},{"url":"https://git.kernel.org/stable/c/398e768d1accd1f5645492ab996005d7aa84a5b0"},{"url":"https://git.kernel.org/stable/c/b0ea441f44ce64fa514a415d4a9e6e2b06e7946c"},{"url":"https://git.kernel.org/stable/c/0ad7a1be44479503dbe5c699759861ef5b8bd70c"},{"url":"https://git.kernel.org/stable/c/1732053c8a6b360e2d5afb1b34fe9779398b072c"}],"tags":["cve.org"],"epss":0.00121,"epssPercentile":0.02219,"ingestedAt":"2026-09-08T15:33:26.994Z","slug":"CVE-2025-71266","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nfs: ntfs3: check return value of indx_find to avoid infinite loop\n\nWe found an infinite loop bug in the ntfs3 file system that can lead to a\nDenial-of-Service (DoS) condition.\n\nA malformed dentry in the ntfs3 filesystem can cause the kernel to hang\nduring the lookup operations. By setting the HAS_SUB_NODE flag in an\nINDEX_ENTRY within a directory's INDEX_ALLOCATION block and manipulating the\nVCN pointer, an attacker can cause the indx_find() function to repeatedly\nread the same block, allocating 4 KB of memory each time. The kernel lacks\nVCN loop detection and depth limits, causing memory exhaustion and an OOM\ncrash.\n\nThis patch adds a return value check for fnd_push() to prevent a memory\nexhaustion vulnerability caused by infinite loops. When the index exceeds the\nsize of the fnd->nodes array, fnd_push() returns -EINVAL. The indx_find()\nfunction checks this return value and stops processing, preventing further\nmemory allocation.\n\n## Affected\n\n- `Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < 14c3188afbedfd5178bbabb8002487ea14b37b56`\n- `Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < 435d34719db0e130f6f0c621d67ed524cc1a7d10`\n- `Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < 68e32694be231c1cdb99b7637a657314e88e1a96`\n- `Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < 398e768d1accd1f5645492ab996005d7aa84a5b0`\n- `Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < b0ea441f44ce64fa514a415d4a9e6e2b06e7946c`\n- `Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < 0ad7a1be44479503dbe5c699759861ef5b8bd70c`\n- `Linux >= 82cae269cfa953032fbb8980a7d554d60fb00b17 < 1732053c8a6b360e2d5afb1b34fe9779398b072c`\n- `Linux 5.15`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}