cbcvebase.
CVE-2025-68266
published 2025-12-16

CVE-2025-68266: In the Linux kernel, the following vulnerability has been resolved: bfs: Reconstruct file type when loading from disk syzbot is reporting that S_IFMT bits of…

PriorityP422high7.8
EPSS
0.17%
6.7th percentile
In the Linux kernel, the following vulnerability has been resolved: bfs: Reconstruct file type when loading from disk syzbot is reporting that S_IFMT bits of inode->i_mode can become bogus when the S_IFMT bits of the 32bits "mode" field loaded from disk are corrupted or when the 32bits "attributes" field loaded from disk are corrupted. A documentation says that BFS uses only lower 9 bits of the "mode" field. But I can't find an explicit explanation that the unused upper 23 bits (especially, the S_IFMT bits) are initialized with 0. Therefore, ignore the S_IFMT bits of the "mode" field loaded from disk. Also, verify that the value of the "attributes" field loaded from disk is either BFS_VREG or BFS_VDIR (because BFS supports only regular files and the root directory).

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d0c5ec1f57d8fbb953f166a27d9d32473dc8f3e4d0c5ec1f57d8fbb953f166a27d9d32473dc8f3e4
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < aeccd6743ee4fdd1ab8cfcbb5b9a20b613418f6daeccd6743ee4fdd1ab8cfcbb5b9a20b613418f6d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8f73336b75bd3457b6f9410f2a0601a238f322388f73336b75bd3457b6f9410f2a0601a238f32238
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a9f626396bfe66f49b743601e862767928237cc0a9f626396bfe66f49b743601e862767928237cc0
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 77899444d46162aeb65f229590c26ba26686422377899444d46162aeb65f229590c26ba266864223
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a8cb796e7e2cb7971311ba236922f5e7e1be77e6a8cb796e7e2cb7971311ba236922f5e7e1be77e6
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 34ab4c75588c07cca12884f2bf6b0347c7a1387234ab4c75588c07cca12884f2bf6b0347c7a13872
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.12-16.17.12-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 2.6.12 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.17.126.17.12
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.626.12.62
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
ubuntulinux-aws-fips

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.