Impact
A crafted NTFS3 disk image can trigger an infinite loop in the ntfs3 driver’s free‑chain walker while mounting. The loop stalls the mounting thread and activates the kernel soft‑lockup watchdog; on systems with panic enabled the kernel may crash. This denial of service prevents normal operation of the affected system.
Affected Systems
Linux machines that use the kernel’s built‑in ntfs3 driver and rely on udisks2 to auto‑mount NTFS volumes are impacted. Distributions such as Arch, Fedora, openSUSE, RHEL, and others that route the NTFS signature to ntfs3 are included. All kernel releases prior to the patch that bounds the traversal are vulnerable.
Risk and Exploitability
The vulnerability is not listed in CISA KEV. The EPSS score is < 1%, and its CVSS score is 5.5, indicating a moderate severity. The failure can be reproduced with a simple disk image, making exploitation straightforward for anyone who can provide the image to the mount process, either via a USB device or an authorised manual mount. The attack causes a soft‑lockup within roughly 22 seconds on multi‑CPU hosts, which can lead to a kernel panic if panic is enabled. No public exploit has been reported, yet the low preparation cost and high impact make it a serious DoS vector.
OpenCVE Enrichment