Skip to main content
EPSS 0.4%top 62%

Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: ntfs3: init run lock for extend inode After setting the inode mode of $Extend to… (CVE-2025-68369)

0
Medium
Published: 12/24/2025 (12/24/2025, 11:16:00 UTC)
Source: GCVE Database
Product: linux-hwe-edge

Description

In the Linux kernel, the following vulnerability has been resolved: ntfs3: init run lock for extend inode After setting the inode mode of $Extend to a regular file, executing the truncate system call will enter the do_truncate() routine, causing the run_lock uninitialized error reported by syzbot. Prior to patch 4e8011ffec79, if the inode mode of $Extend was not set to a regular file, the do_truncate() routine would not be entered. Add the run_lock initialization when loading $Extend. syzbot reported: INFO: trying to register non-static key. Call Trace: dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120 assign_lock_key+0x133/0x150 kernel/locking/lockdep.c:984 register_lock_class+0x105/0x320 kernel/locking/lockdep.c:1299 __lock_acquire+0x99/0xd20 kernel/locking/lockdep.c:5112 lock_acquire+0x120/0x360 kernel/locking/lockdep.c:5868 down_write+0x96/0x1f0 kernel/locking/rwsem.c:1590 ntfs_set_size+0x140/0x200 fs/ntfs3/inode.c:860 ntfs_extend+0x1d9/0x970 fs/ntfs3/file.c:387 ntfs_setattr+0x2e8/0xbe0 fs/ntfs3/file.c:808

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

Affected versions
<6.8.0-1052.55~22.04.1<6.8.0-1059.65~22.04.1<6.8.0-1054.57~22.04.1<6.8.0-110.110~22.04.1<6.8.0-1051.51~22.04.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 18:53:31 UTC

Technical Analysis

The Linux kernel ntfs3 driver had a vulnerability where setting the inode mode of $Extend to a regular file and then executing the truncate system call would enter the do_truncate() routine with an uninitialized run_lock, causing a locking error. This issue was fixed by adding run_lock initialization during $Extend loading. The vulnerability was reported by syzbot and affects kernel code paths related to inode truncation and locking in the ntfs3 filesystem driver.

Potential Impact

The vulnerability causes an uninitialized run_lock error in the kernel's ntfs3 driver during inode truncation operations, which can lead to kernel instability or denial of service (crash). There is no indication of confidentiality or integrity impact. The CVSS vector indicates no confidentiality or integrity impact but high availability impact.

Mitigation Recommendations

A patch has been applied to initialize the run_lock when loading $Extend, resolving the vulnerability. Users should update to the Linux kernel version that includes this fix (commit 4e8011ffec79 or later). Patch status is confirmed by the vendor fix referenced in the description.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-9m7w-275g-v9x3
Osv Schema Version
1.4.0
Aliases
["CVE-2025-68369"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a6b72d29c2644c7f8477cc3

Added to database: 07/30/2026, 15:50:42 UTC

Last enriched: 07/30/2026, 18:53:31 UTC

Last updated: 09/10/2026, 19:36:51 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses