In the Linux kernel, the following vulnerability has been resolved:
exfat: fix improper check of dentry.stream.valid_size
We found an infinite loop bug in the exFAT file system that can lead to a
Denial-of-Service (DoS) condition. When a dentry in an exFAT filesystem is
malformed, the following system calls — SYS_openat, SYS_ftruncate, and
SYS_pwrite64 — can cause the kernel to hang.
Root cause analysis shows that the size validation code in exfat_find()
does not check whether dentry.stream.valid_size is negative. As a result,
the system calls mentioned above can succeed and eventually trigger the DoS
issue.
This patch adds a check for negative dentry.stream.valid_size to prevent
this vulnerability.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-12-06 22:15
Updated : 2026-06-17 09:21
NVD link : CVE-2025-40287
Mitre link : CVE-2025-40287
CVE.ORG link : CVE-2025-40287
JSON object : View
Products Affected
No product.
CWE
No CWE.
