PT-2025-53006 · Linux+3 · Linux Kernel+3

Published

2025-11-21

·

Updated

2026-05-26

·

CVE-2025-68740

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the Integrity Measurement Architecture (IMA) subsystem. Specifically, the ima match rules() function incorrectly handles error codes returned by ima filter rule match(). If ima filter rule match() returns -ENOENT, indicating a NULL rule, the check 'if (!rc)' is bypassed, leading to a false positive match. This results in extra files being measured by IMA. The issue occurs when the SELinux policy module is unloaded via 'semodule -d', and an IMA measurement is triggered before ima lsm rules is updated. The call trace includes functions such as selinux audit rule match(), ima match rules(), ima match policy(), and process measurement(). The root cause is an incorrect conditional check that allows error codes to be misinterpreted as successful matches.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Initialization

Weakness Enumeration

Related Identifiers

AZL-73132
BDU:2026-01151
CVE-2025-68740
ECHO-E341-9110-DE85
OESA-2026-2417
OESA-2026-2418
OPENSUSE-SU-2026:10039-1
OPENSUSE-SU-2026:10301-1
OPENSUSE-SU-2026:20145-1
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:0473-1
SUSE-SU-2026:20207-1
SUSE-SU-2026:20220-1
SUSE-SU-2026:20228-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8116-1
USN-8141-1
USN-8152-1
USN-8163-1
USN-8163-2
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8243-1
USN-8258-1
USN-8260-1
USN-8261-1
USN-8265-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu