Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject index allocation if $BITMAP is empty but blocks exist Index… (CVE-2025-40067)
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject index allocation if $BITMAP is empty but blocks exist Index allocation requires at least one bit in the $BITMAP attribute to track usage of index entries. If the bitmap is empty while index blocks are already present, this reflects on-disk corruption. syzbot triggered this condition using a malformed NTFS image. During a rename() operation involving a long filename (which spans multiple index entries), the empty bitmap allowed the name to be added without valid tracking. Subsequent deletion of the original entry failed with -ENOENT, due to unexpected index state. Reject such cases by verifying that the bitmap is not empty when index blocks exist.
AI Analysis
Technical Summary
The Linux kernel NTFS3 driver had a vulnerability where index allocation proceeded despite the $BITMAP attribute being empty while index blocks were present. This inconsistency reflects on-disk corruption and was triggered by malformed NTFS images during rename operations involving long filenames spanning multiple index entries. The empty bitmap allowed adding names without proper tracking, causing subsequent deletion failures with -ENOENT errors due to unexpected index states. The fix enforces verification that the bitmap is not empty when index blocks exist, preventing this inconsistent state.
Potential Impact
This vulnerability can cause filesystem inconsistencies leading to failures in file operations such as renaming and deleting files with long filenames on NTFS partitions. The CVSS vector indicates local attack vector with low complexity, no privileges required, user interaction needed, and high impact on confidentiality, integrity, and availability. However, no known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since this is a Linux kernel vulnerability, monitor for official kernel updates addressing CVE-2025-40067 and apply them promptly once available.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject index allocation if $BITMAP is empty but blocks exist Index… (CVE-2025-40067)
Description
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject index allocation if $BITMAP is empty but blocks exist Index allocation requires at least one bit in the $BITMAP attribute to track usage of index entries. If the bitmap is empty while index blocks are already present, this reflects on-disk corruption. syzbot triggered this condition using a malformed NTFS image. During a rename() operation involving a long filename (which spans multiple index entries), the empty bitmap allowed the name to be added without valid tracking. Subsequent deletion of the original entry failed with -ENOENT, due to unexpected index state. Reject such cases by verifying that the bitmap is not empty when index blocks exist.
CVSS v3.1
Score 7.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel NTFS3 driver had a vulnerability where index allocation proceeded despite the $BITMAP attribute being empty while index blocks were present. This inconsistency reflects on-disk corruption and was triggered by malformed NTFS images during rename operations involving long filenames spanning multiple index entries. The empty bitmap allowed adding names without proper tracking, causing subsequent deletion failures with -ENOENT errors due to unexpected index states. The fix enforces verification that the bitmap is not empty when index blocks exist, preventing this inconsistent state.
Potential Impact
This vulnerability can cause filesystem inconsistencies leading to failures in file operations such as renaming and deleting files with long filenames on NTFS partitions. The CVSS vector indicates local attack vector with low complexity, no privileges required, user interaction needed, and high impact on confidentiality, integrity, and availability. However, no known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since this is a Linux kernel vulnerability, monitor for official kernel updates addressing CVE-2025-40067 and apply them promptly once available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-rxpf-8w5h-7fch
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-40067"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6b72d69c2644c7f847af0f
Added to database: 07/30/2026, 15:50:46 UTC
Last enriched: 07/30/2026, 16:23:40 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.