In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: don't hold ni_lock when calling truncate_setsize()
syzbot is reporting hung task at do_user_addr_fault() [1], for there is a silent deadlock between PG_locked bit and ni_lock lock.
Since filemap_update_page() calls filemap_read_folio() after calling folio_trylock() which will set PG_locked bit, ntfs_truncate() must not call truncate_setsize() which will wait for PG_locked bit to be cleared when holding ni_lock lock.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfo-common-aarch64Upgrade kernel-toolsUpgrade python-perfUpgrade kernel-debuginfoUpgrade kernel-develUpgrade kernel-headersUpgrade kernel-livepatch-5.15.90-54.138Upgrade perf-debuginfoUpgrade python-perf-debuginfoUpgrade perfUpgrade kernel-tools-develUpgrade kernelUpgrade bpftool-debuginfoUpgrade kernel-tools-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade bpftool | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade linux | Sep 17, 2025 | Sep 17, 2025 |
| Ubuntu | — | Upgrade linux-lowlatencyUpgrade linux-intel-iotg-5.15Upgrade linux-raspiUpgrade linux-oracleUpgrade linux-aws-5.15Upgrade linux-nvidiaUpgrade linux-bluefieldUpgrade linux-gcp-5.15Upgrade linux-ibmUpgrade linux-azureUpgrade linux-hwe-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-kvmUpgrade linux-azure-5.15Upgrade linux-realtimeUpgrade linux-intel-iotgUpgrade linux-gkeopUpgrade linux-oracle-5.15Upgrade linux-riscv-5.15Upgrade linux-gkeUpgrade linux-gcpUpgrade linux-intel-iot-realtimeUpgrade linuxUpgrade linux-awsUpgrade linux-nvidia-tegra-5.15 | Sep 19, 2025 | Sep 16, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub