CVE-2025-71311: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN reports an uninitialized value in longest_match_std(), invoked from ntfs_compress_write(). When new folios are allocated without being marked uptodate and ni_read_frame() is skipped because the caller expects the frame to be completely overwritten, some reserved folios may remain only partially filled, leaving the rest memory uninitialized.
Affected products
- Linux Linux Kernel: from 6.11, before 6.12.75 (fixed in 6.12.75); from 6.13, before 6.18.14 (fixed in 6.18.14); from 6.19, before 6.19.4 (fixed in 6.19.4)
Published 2026-05-27. Last modified 2026-07-30.