cbcvebase.
CVE-2025-68243
published 2025-12-16

CVE-2025-68243: In the Linux kernel, the following vulnerability has been resolved: NFS: Check the TLS certificate fields in nfs_match_client() If the TLS security policy is…

PriorityP430high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.07%
0.1th percentile
In the Linux kernel, the following vulnerability has been resolved: NFS: Check the TLS certificate fields in nfs_match_client() If the TLS security policy is of type RPC_XPRTSEC_TLS_X509, then the cert_serial and privkey_serial fields need to match as well since they define the client's identity, as presented to the server.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.9-1 (forky)linux 6.17.9-1 (forky)
linuxlinux
linuxlinux>= 90c9550a8d65fb9b1bf87baf97a04ed91bf61b33 < b8fa37219074811c04d4ecb742c73e2b296da6a8b8fa37219074811c04d4ecb742c73e2b296da6a8
linuxlinux>= 90c9550a8d65fb9b1bf87baf97a04ed91bf61b33 < fb2cba0854a7f315c8100a807a6959b99d72479efb2cba0854a7f315c8100a807a6959b99d72479e
linuxlinux_kernel>= 0 < 6.17.9-16.17.9-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.17.0 < 6.17.96.17.9
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.