You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
ntfs3
About this tag
The ntfs3 tag covers discussions about the Linux kernel's NTFS3 filesystem driver, particularly its security vulnerabilities and patches. Recent threads focus on CVE-2025-38167, which affects Azure Linux due to its inclusion of upstream NTFS3 code, and CVE-2024-27407, a local buffer overflow in the mi_enum_attr() routine that can corrupt kernel memory and enable privilege escalation. Topics include Microsoft's attestation practices, remediation priorities, and mitigation strategies for affected systems. The tag is relevant for IT security teams managing Linux systems that mount NTFS volumes.
The short, practical answer is: Microsoft has publicly attested that Azure Linux includes the upstream NTFS3 code referenced by CVE‑2025‑38167 and is therefore potentially affected, but that attestation is product‑scoped — it is not a technical proof that Azure Linux is the only Microsoft...
A subtle arithmetic mistake in the Linux kernel’s NTFS3 driver has been fixed, closing CVE-2024-27407 — a locally exploitable buffer‑overflow vulnerability in the mi_enum_attr() routine that, if triggered on systems that mount NTFS volumes, can corrupt kernel memory, crash the host, and in the...