CVE-2025-68351: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: exfat: fix refcount leak in exfat_find Fix refcount leaks in `exfat_find` related to `exfat_get_dentry_set`. Function `exfat_get_dentry_set` would increase the reference counter of `es->bh` on success. Therefore, `exfat_put_dentry_set` must be called after `exfat_get_dentry_set` to ensure refcount consistency. This patch relocate two checks to avoid possible leaks.

Affected products

  • Linux Linux Kernel: from 6.12.23, before 6.12.68 (fixed in 6.12.68); from 6.12.59, before 6.13 (fixed in 6.13); from 6.13.11, before 6.14 (fixed in 6.14); from 6.14.1, before 6.18.2 (fixed in 6.18.2); version 6.14 only

Published 2025-12-24. Last modified 2026-06-17.