VulnerabilityModified
CVE-2025-38707
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add sanity check for file name The length of the file name should be smaller than the directory entry size.
HIGH 7.8EPSS 0.17%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add sanity check for file name The length of the file name should be smaller than the directory entry size.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.17% probability · 6th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/27ee9a42b245efe6529e28b03453291a775cb3e4Patch
- https://git.kernel.org/stable/c/2ac47f738ddfc1957a33be163bc97ee8f78e85a6Patch
- https://git.kernel.org/stable/c/3572737a768dadea904ebc4eb34b6ed575bb72d9Patch
- https://git.kernel.org/stable/c/b51642fc52d1c7243a9361555d5c4b24d7569d7ePatch
- https://git.kernel.org/stable/c/bde58c1539f3ffddffc94d64007de16964e6b8ebPatch
- https://git.kernel.org/stable/c/e841ecb139339602bc1853f5f09daa5d1ea920a2Patch
- https://git.kernel.org/stable/c/f99eb9a641f4ef927d8724f4966dcfd1f0e9f835Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlMailing List, Third Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.