CVE-2025-68183 — Linux vulnerability
34 documents8 sources
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 90.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr
Currently when both IMA and EVM are in fix mode, the IMA signature will
be reset to IMA hash if a program first stores IMA signature in
security.ima and then writes/removes some other security xattr for the
file.
For example, on Fedora, after booting the kernel with "ima_appraise=fix
evm=fix ima_policy=appraise_tcb" and installing rpm-plugin-ima,
installi…
Affected Packages5 packages
▶CVEListV5linux/linuxe3ccfe1ad7d895487977ef64eda3441d16c9851a — d2993a7e98eb70c737c6f5365a190e79c72b8407+4
🔴Vulnerability Details
16📋Vendor Advisories
15🕵️Threat Intelligence
1💬Community
1Bugzilla▶
CVE-2025-68183 kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr↗2025-12-16