PT-2025-52885 · Linux+4 · Linux Kernel+4

Published

2025-11-23

·

Updated

2026-05-11

·

CVE-2025-68349

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the NFSv4/pNFS implementation where the NFS INO LAYOUTCOMMIT flag is not properly cleared in the pnfs mark layout stateid invalid function. This can lead to a crash when a layout is null during specific call stacks involving write inode and pnfs layoutcommit inode. The issue arises because pnfs set layoutcommit relies on the layout segment reference count, and failing to clear NFS INO LAYOUTCOMMIT can result in attempts to reference a null layout.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2026:2264
ALSA-2026:2378
ALSA-2026:2721
ALSA-2026:2722
AZL-73057
BDU:2026-02508
CVE-2025-68349
ECHO-3941-2D33-1F31
OESA-2026-1009
OESA-2026-1010
OESA-2026-1011
OESA-2026-1759
OESA-2026-1760
OESA-2026-1761
OPENSUSE-SU-2026:10039-1
OPENSUSE-SU-2026:10301-1
OPENSUSE-SU-2026:20287-1
RHSA-2026:2264
RHSA-2026:2352
RHSA-2026:2378
RHSA-2026:2490
RHSA-2026:2664
RHSA-2026:2721
RHSA-2026:2722
RHSA-2026:2766
RHSA-2026:3267
RHSA-2026:3277
RHSA-2026:3293
RHSA-2026:3358
RHSA-2026:3360
RHSA-2026:3375
RHSA-2026:3634
RHSA-2026:3685
RHSA-2026:6193
SUSE-SU-2026:0447-1
SUSE-SU-2026:0472-1
SUSE-SU-2026:0473-1
SUSE-SU-2026:0587-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8116-1
USN-8141-1
USN-8152-1
USN-8163-1
USN-8163-2
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8243-1
USN-8258-1
USN-8260-1
USN-8261-1
USN-8265-1

Affected Products

Debian
Linuxmint
Linux Kernel
Rocky Linux
Ubuntu