cbcvebase.
CVE-2025-68239
published 2025-12-16

CVE-2025-68239: In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write access before closing files opened by open_exec()…

PriorityP425high7.1
EPSS
0.17%
7.1th percentile
In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write access before closing files opened by open_exec() bm_register_write() opens an executable file using open_exec(), which internally calls do_open_execat() and denies write access on the file to avoid modification while it is being executed. However, when an error occurs, bm_register_write() closes the file using filp_close() directly. This does not restore the write permission, which may cause subsequent write operations on the same file to fail. Fix this by calling exe_file_allow_write_access() before filp_close() to restore the write permission properly.

Affected

68 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.9-1 (forky)linux 6.17.9-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.226 < 4.154.15
linuxlinux>= 4.19.181 < 4.204.20
linuxlinux>= 4.9.262 < 4.104.10
linuxlinux>= 5.10.24 < 5.115.11
linuxlinux>= 5.11.7 < 5.125.12
linuxlinux>= 5.4.106 < 5.55.5
linuxlinux>= e7850f4d844e0acfac7e570af611d89deade3146 < 54274ff90488b6c0f595a6518faed3cf0bc966eb54274ff90488b6c0f595a6518faed3cf0bc966eb
linuxlinux>= e7850f4d844e0acfac7e570af611d89deade3146 < 480ac88431703f2adbb8e6b5bd73c3f3cf9f3d7f480ac88431703f2adbb8e6b5bd73c3f3cf9f3d7f
linuxlinux>= e7850f4d844e0acfac7e570af611d89deade3146 < fbab8c08e1a6dbaef81e22d672a7647553101d16fbab8c08e1a6dbaef81e22d672a7647553101d16
linuxlinux>= e7850f4d844e0acfac7e570af611d89deade3146 < 6cce7bc7fac8471c832696720d9c8f2a976d9c546cce7bc7fac8471c832696720d9c8f2a976d9c54
linuxlinux>= e7850f4d844e0acfac7e570af611d89deade3146 < e785f552ab04dbca01d31f0334f4561240b04459e785f552ab04dbca01d31f0334f4561240b04459
linuxlinux>= e7850f4d844e0acfac7e570af611d89deade3146 < 90f601b497d76f40fa66795c3ecf625b6aced9fd90f601b497d76f40fa66795c3ecf625b6aced9fd
linuxlinux_kernel>= 0 < 6.17.9-16.17.9-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.12.0 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13.0 < 6.17.96.17.9
linuxlinux_kernel>= 6.2.0 < 6.6.1306.6.130

CVSS provenance

vendor_ubuntu7.1HIGH
vendor_msrc6.2MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.