CVE-2025-71311
📛 CVE Title
fs/ntfs3: Initialize new folios before use
Description
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN reports an uninitialized value in longest_match_std(), invoked from ntfs_compress_write(). When new folios are allocated without being marked uptodate and ni_read_frame() is skipped because the caller expects the frame to be completely overwritten, some reserved folios may remain only partially filled, leaving the rest memory uninitialized.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Linux
- CVSS severity
- high
- CVSS score
- 7.1 / 10
- CVSS vector
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H- Effective score
- 7.1 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- 2026-05-27
- Published
- 2026-05-27 12:24 UTC
- Last updated
- 2026-05-27 12:24 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/71xxx/CVE-2025-71311.json
- Linked Threat
- CVE-2025-71311 — CVE-2025-71311
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-05-27 14:16:43 UTC
- NVD last modified
- 2026-06-25 21:04:05 UTC
- NVD CVSS v3.1
- 5.5 / 10 MEDIUM source: nvd@nist.gov
- NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H- Exploitability subscore
- 1.8 / 10
- Impact subscore
- 3.6 / 10
- EPSS score
- 0.0015 (probability of exploitation in next 30 days)
- EPSS percentile
- 5.11% vs all CVEs — higher = more likely to be exploited, as of 2026-07-26
NVD-assigned CWE(s):
CWE-908
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-07-27 11:04 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2025-209965 - Assigner
- Linux
- Published
- May 27, 2026, 12:24:02 PM
- Updated
- May 27, 2026, 12:24:02 PM
- EUVD base score
- 0.0 / 10
- EUVD-reported EPSS
- 0.1600
- Vendors
- Linux
- Products
-
Linux (patch: 6.12.75)Linux (patch: 6.18.14)Linux (584f60ba22f79c89e6708ab82a5b5d9b8fa21fb2 <f223ebffa185cc8da934333c5a31ff2d4f992dc9)Linux (584f60ba22f79c89e6708ab82a5b5d9b8fa21fb2 <5a30cc03bde169ad558695b26da6ea7e55f6194a)Linux (6.11)Linux (patch: 6.19.4)Linux (584f60ba22f79c89e6708ab82a5b5d9b8fa21fb2 <41d79f8e2a36622d148719bf7c18b46ac1264284)Linux (patch: 7.0)Linux (584f60ba22f79c89e6708ab82a5b5d9b8fa21fb2 <dd6c81527d097b3b0bf5a15c2fdc9657d045144c)Linux (patch: 0)
- Aliases
-
GHSA-55mq-jw86-3h27
ENISA description: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN reports an uninitialized value in longest_match_std(), invoked from ntfs_compress_write(). When new folios are allocated without being marked uptodate and ni_read_frame() is skipped because the caller expects the frame to be completely overwritten, some reserved folios may remain only partially filled, leaving the rest memory uninitialized.
EUVD references (4)
Affected products (2)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Linux | Linux |
584f60ba22f79c89e6708ab82a5b5d9b8fa21fb2 (affected),
584f60ba22f79c89e6708ab82a5b5d9b8fa21fb2 (affected),
584f60ba22f79c89e6708ab82a5b5d9b8fa21fb2 (affected),
584f60ba22f79c89e6708ab82a5b5d9b8fa21fb2 (affected)
|
— |
| Linux | Linux |
6.11 (affected),
0 (unaffected),
6.12.75 (unaffected),
6.18.14 (unaffected),
6.19.4 (unaffected),
7.0 (unaffected)
|
— |
Affected products — CPE 2.3 (1) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendor references (4)
References embedded in the original CVE record by the assigning CNA.
Web references (7)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://git.kernel.org/stable/c/41d79f8e2a36622d148719bf7c18b46ac1264284 tenable:git.kernel.org
- https://git.kernel.org/stable/c/5a30cc03bde169ad558695b26da6ea7e55f6194a tenable:git.kernel.org
- https://git.kernel.org/stable/c/dd6c81527d097b3b0bf5a15c2fdc9657d045144c tenable:git.kernel.org
- https://git.kernel.org/stable/c/f223ebffa185cc8da934333c5a31ff2d4f992dc9 tenable:git.kernel.org
- https://nvd.nist.gov/vuln/detail/CVE-2025-71311 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2025-71311 tenable:www.cve.org
- https://www.first.org/epss/ tenable:www.first.org
NVD-tagged references (4)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://git.kernel.org/stable/c/41d79f8e2a36622d148719bf7c18b46ac1264284 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/5a30cc03bde169ad558695b26da6ea7e55f6194a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/dd6c81527d097b3b0bf5a15c2fdc9657d045144c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/f223ebffa185cc8da934333c5a31ff2d4f992dc9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:krebsonsecurity.com
Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. This final Patch Tuesday of 2025 tackles one zero-day bug that is already ...
2026-06-04 00:02 UTC -
web:petri.com
If a Group Policy setting is available to roll back a fix , it is included in the Windows Update KB article and release notes as a mitigation for a known issue.
2026-06-04 00:02 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-04 00:02 UTC -
web:www.bleepingcomputer.com
Microsoft says customers in restricted network environments may encounter Windows Update failures after installing the January 2026 optional non-security preview updates.
2026-06-04 00:02 UTC -
web:www.bugcrowd.com
Vulnerability mitigation is typically considered a temporary or interim solution. While mitigation measures can reduce the immediate risk associated with vulnerabilities, they may not provide a permanent fix . Organizations should aim to prioritize and plan for complete vulnerability remediation whenever feasible and allocate resources accordingly.
2026-06-04 00:02 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-06-04 00:02 UTC -
web:www.lansweeper.com
Which vulnerabilities, issues, and other things did Microsoft update? Discover what's new using Lansweeper's Patch Tuesday November 2025 summary.
2026-06-04 00:02 UTC -
web:www.techrepublic.com
Microsoft's April 2026 Patch Tuesday fixes 165 vulnerabilities, including two zero-days, in one of the company's largest monthly security updates.
2026-06-04 00:02 UTC -
web:www.windowscentral.com
A faulty BitLocker configuration is forcing some PCs into BitLocker recovery mode after the April 2026 update, but there's a workaround to resolve this issue.
2026-06-04 00:02 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-06-04 00:02 UTC -
web:cyberpress.org
Microsoft's June 2026 Patch Tuesday cumulative update for Windows 11 KB5094126 (OS Build 26100.8655/26200.8457) is generating widespread backlash from IT administrators and end users after triggering a series of severe post-installation failures, including BitLocker recovery lockouts, system freezes, broken OneDrive File Explorer integration, and LAN connectivity disruptions.
2026-06-19 02:27 UTC -
web:nvd.nist.gov
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
2026-06-19 02:27 UTC -
web:support.microsoft.com
It includes updates from previous security and non-security releases, along with an additional fix . To learn more about differences between security updates, optional non-security preview updates, out-of-band (OOB) updates, and continuous innovation, see Windows monthly updates explained.
2026-06-19 02:27 UTC -
web:www.bleepingcomputer.com
Microsoft has released Windows 11 KB5077181 and KB5075941 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
2026-06-19 02:27 UTC -
web:www.malwarebytes.com
Microsoft says it's working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.
2026-06-19 02:27 UTC -
web:www.ninjaone.com
Catalog of Microsoft KB updates with insights on performance & user sentiment. Find out what's working, what's not, & make informed decisions.
2026-06-19 02:27 UTC -
web:www.pcworld.com
Microsoft has released an emergency update for Windows 11. Update KB5086672 is an out-of-band update intended to resolve issues caused by the optional Windows update KB5079391 from late March ...
2026-06-19 02:27 UTC -
web:www.sentinelone.com
CVE - 2025 -21311 is a privilege escalation vulnerability in Windows 11 24h2 NTLM V1. Learn about its impact, affected versions, and mitigation methods.
2026-06-19 02:27 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2025-71311.json.
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ntfs3/file.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "dd6c81527d097b3b0bf5a15c2fdc9657d045144c",
"status": "affected",
"version": "584f60ba22f79c89e6708ab82a5b5d9b8fa21fb2",
"versionType": "git"
},
{
"lessThan": "5a30cc03bde169ad558695b26da6ea7e55f6194a",
"status": "affected",
"version": "584f60ba22f79c89e6708ab82a5b5d9b8fa21fb2",
"versionType": "git"
},
{
"lessThan": "41d79f8e2a36622d148719bf7c18b46ac1264284",
"status": "affected",
"version": "584f60ba22f79c89e6708ab82a5b5d9b8fa21fb2",
"versionType": "git"
},
{
"lessThan": "f223ebffa185cc8da934333c5a31ff2d4f992dc9",
"status": "affected",
"version": "584f60ba22f79c89e6708ab82a5b5d9b8fa21fb2",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ntfs3/file.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"lessThan": "6.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.14",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "6.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "6.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Initialize new folios before use\n\nKMSAN reports an uninitialized value in longest_match_std(), invoked\nfrom ntfs_compress_write(). When new folios are allocated without being\nmarked uptodate and ni_read_frame() is skipped because the caller expects\nthe frame to be completely overwritten, some reserved folios may remain\nonly partially filled, leaving the rest memory uninitialized."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-27T12:24:02.532Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/dd6c81527d097b3b0bf5a15c2fdc9657d045144c"
},
{
"url": "https://git.kernel.org/stable/c/5a30cc03bde169ad558695b26da6ea7e55f6194a"
},
{
"url": "https://git.kernel.org/stable/c/41d79f8e2a36622d148719bf7c18b46ac1264284"
},
{
"url": "https://git.kernel.org/stable/c/f223ebffa185cc8da934333c5a31ff2d4f992dc9"
}
],
"title": "fs/ntfs3: Initialize new folios before use",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2025-71311",
"datePublished": "2026-05-27T12:24:02.532Z",
"dateReserved": "2026-05-27T12:23:27.414Z",
"dateUpdated": "2026-05-27T12:24:02.532Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}