Linux Kernel NTFS3 File Truncation Error Handling Vulnerability

Vulnerability

A vulnerability exists in the Linux kernel's NTFS3 file system handling, specifically in the file truncation process. When the function 'attr_set_size()' fails while reducing file size, the error is not properly addressed, potentially leaving the inode in an inconsistent state. This issue has been corrected in the Linux kernel stable tree.

Impact

The vulnerability could lead to file system inconsistencies, where inodes are not accurately reflecting the state of the files they represent. This can cause various issues, such as data corruption or unexpected behavior in file operations.

Added: May 6, 2026, 5:54 PM
Updated: May 6, 2026, 5:54 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
3.5
remediation
7.7
relevance
7.6
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.