PT-2025-53002 · Linux+3 · Linux Kernel+3

Published

2025-12-24

·

Updated

2026-05-07

·

CVE-2025-68736

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel landlock subsystem had a flaw in how it handled disconnected directories. These directories could appear when files or directories were accessed through a bind mount but had been moved or renamed from the original source, making them inaccessible from the mount point. Previously, access rights were collected by traversing the filesystem hierarchy without considering the mount point, potentially leading to inconsistent access results and access right widening. This issue could occur when a sandboxed task had write access to the source of the bind mount and read access to the mount point itself. The landlock subsystem has been updated to consider the filesystem hierarchy and the mount point when evaluating access rights for files and directories opened from disconnected directories, ensuring that renames do not widen access rights. The fix also removes a warning canary and corrects a related comment in the collect domain accesses() function. Files with stored access rights are not impacted by this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

AZL-73084
CVE-2025-68736
ECHO-4F65-D799-3305
OPENSUSE-SU-2026:10039-1
OPENSUSE-SU-2026:10301-1
OPENSUSE-SU-2026:20145-1
SUSE-SU-2026:0962-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:20207-1
SUSE-SU-2026:20220-1
SUSE-SU-2026:20228-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8177-1
USN-8177-2
USN-8183-1
USN-8183-2
USN-8245-1
USN-8257-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu