CVE-2025-68185: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing Theoretically it's an oopsable race, but I don't believe one can manage to hit it on real hardware; might become doable on a KVM, but it still won't be easy to attack. Anyway, it's easy to deal with - since xdr_encode_hyper() is just a call of put_unaligned_be64(), we can put that under ->d_lock and be done with that.

Affected products

  • Linux Linux: from 2.6.12, before 5.4.302 (fixed in 5.4.302); from 5.5, before 5.10.247 (fixed in 5.10.247); from 5.11, before 5.15.197 (fixed in 5.15.197); from 5.16, before 6.1.159 (fixed in 6.1.159); from 6.2, before 6.6.117 (fixed in 6.6.117); from 6.7, before 6.12.58 (fixed in 6.12.58); …

Published 2025-12-16. Last modified 2026-06-17.