CVE-2025-68728
In the Linux kernel, the following vulnerability has been resolved:
ntfs3: fix uninit memory after failed mi_read in mi_format_new
Fix a KMSAN un-init bug found by syzkaller.
ntfs_get_bh() expects a buffer from sb_getblk(), that buffer may not be uptodate. We do not bring the buffer uptodate before setting it as uptodate. If the buffer were to not be uptodate, it could mean adding a buffer with un-init data to the mi record. Attempting to load that record will trigger KMSAN.
Avoid this by setting the buffer as uptodate, if it’s not already, by overwriting it.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/46f2a881e5a7311d41551edb3915e4d4e8802341
- https://git.kernel.org/stable/c/73e6b9dacf72a1e7a4265eacca46f8f33e0997d6
- https://git.kernel.org/stable/c/7ce8f2028dfccb2161b905cf8ab85cdd9e93909c
- https://git.kernel.org/stable/c/81ffe9a265df3e41534726b852ab08792e3d374d
- https://git.kernel.org/stable/c/8bf729b96303bb862d7c6dc05edcf51274ae04cf
- https://git.kernel.org/stable/c/afb144bc8e920db43a23e996eb0a6f9bdea84341
- https://git.kernel.org/stable/c/c70b3abfd530c7f574bc25a5f84707e6fdf0def8
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-68728",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4342306f0f0d5ff4315a204d315c1b51b914fca5",
"lessThan": "afb144bc8e920db43a23e996eb0a6f9bdea84341",
"versionType": "git"
},
{
"status": "affected",
"version": "4342306f0f0d5ff4315a204d315c1b51b914fca5",
"lessThan": "c70b3abfd530c7f574bc25a5f84707e6fdf0def8",
"versionType": "git"
},
{
"status": "affected",
"version": "4342306f0f0d5ff4315a204d315c1b51b914fca5",
"lessThan": "8bf729b96303bb862d7c6dc05edcf51274ae04cf",
"versionType": "git"
},
{
"status": "affected",
"version": "4342306f0f0d5ff4315a204d315c1b51b914fca5",
"lessThan": "7ce8f2028dfccb2161b905cf8ab85cdd9e93909c",
"versionType": "git"
},
{
"status": "affected",
"version": "4342306f0f0d5ff4315a204d315c1b51b914fca5",
"lessThan": "46f2a881e5a7311d41551edb3915e4d4e8802341",
"versionType": "git"
},
{
"status": "affected",
"version": "4342306f0f0d5ff4315a204d315c1b51b914fca5",
"lessThan": "81ffe9a265df3e41534726b852ab08792e3d374d",
"versionType": "git"
},
{
"status": "affected",
"version": "4342306f0f0d5ff4315a204d315c1b51b914fca5",
"lessThan": "73e6b9dacf72a1e7a4265eacca46f8f33e0997d6",
"versionType": "git"
}
],
"programFiles": [
"fs/ntfs3/fsntfs.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.198",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.160",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.120",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.63",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.17.13",
"versionType": "semver",
"lessThanOrEqual": "6.17.*"
},
{
"status": "unaffected",
"version": "6.18.2",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/ntfs3/fsntfs.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-12-24T11:16:02.100",
"references": [
{
"url": "https://git.kernel.org/stable/c/46f2a881e5a7311d41551edb3915e4d4e8802341",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/73e6b9dacf72a1e7a4265eacca46f8f33e0997d6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7ce8f2028dfccb2161b905cf8ab85cdd9e93909c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/81ffe9a265df3e41534726b852ab08792e3d374d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8bf729b96303bb862d7c6dc05edcf51274ae04cf",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/afb144bc8e920db43a23e996eb0a6f9bdea84341",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c70b3abfd530c7f574bc25a5f84707e6fdf0def8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs3: fix uninit memory after failed mi_read in mi_format_new\n\nFix a KMSAN un-init bug found by syzkaller.\n\nntfs_get_bh() expects a buffer from sb_getblk(), that buffer may not be\nuptodate. We do not bring the buffer uptodate before setting it as\nuptodate. If the buffer were to not be uptodate, it could mean adding a\nbuffer with un-init data to the mi record. Attempting to load that record\nwill trigger KMSAN.\n\nAvoid this by setting the buffer as uptodate, if it’s not already, by\noverwriting it."
}
],
"lastModified": "2026-06-17T09:59:29.393",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}