CVE-2025-68239: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write access before closing files opened by open_exec() bm_register_write() opens an executable file using open_exec(), which internally calls do_open_execat() and denies write access on the file to avoid modification while it is being executed. However, when an error occurs, bm_register_write() closes the file using filp_close() directly. This does not restore the write permission, which may cause subsequent write operations on the same file to fail. Fix this by calling exe_file_allow_write_access() before filp_close() to restore the write permission properly.

Affected products

  • Linux Linux: from 4.9.262, before 4.10 (fixed in 4.10); from 4.14.226, before 4.15 (fixed in 4.15); from 4.19.181, before 4.20 (fixed in 4.20); from 5.4.106, before 5.5 (fixed in 5.5); from 5.10.24, before 5.11 (fixed in 5.11); from 5.11.7, before 5.12 (fixed in 5.12); …

Published 2025-12-16. Last modified 2026-06-17.