cbcvebase.
CVE-2025-68297
published 2025-12-16

CVE-2025-68297: In the Linux kernel, the following vulnerability has been resolved: ceph: fix crash in process_v2_sparse_read() for encrypted directories The crash in…

PriorityP422high7.8
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ceph: fix crash in process_v2_sparse_read() for encrypted directories The crash in process_v2_sparse_read() for fscrypt-encrypted directories has been reported. Issue takes place for Ceph msgr2 protocol in secure mode. It can be reproduced by the steps: sudo mount -t ceph :/ /mnt/cephfs/ -o name=admin,fs=cephfs,ms_mode=secure (1) mkdir /mnt/cephfs/fscrypt-test-3 (2) cp area_decrypted.tar /mnt/cephfs/fscrypt-test-3 (3) fscrypt encrypt --source=raw_key --key=./my.key /mnt/cephfs/fscrypt-test-3 (4) fscrypt lock /mnt/cephfs/fscrypt-test-3 (5) fscrypt unlock --key=my.key /mnt/cephfs/fscrypt-test-3 (6) cat /mnt/cephfs/fscrypt-test-3/area_decrypted.tar (7) Issue has been triggered [ 408.072247] ------------[ cut here ]------------ [ 408.072251] WARNING: CPU: 1 PID: 392 at net/ceph/messenger_v2.c:865 ceph_con_v2_try_read+0x4b39/0x72f0 [ 408.072267] Modules linked in: intel_rapl_msr intel_rapl_common intel_uncore_frequency_common intel_pmc_core pmt_telemetry pmt_discovery pmt_class intel_pmc_ssram_telemetry intel_vsec kvm_intel joydev kvm irqbypass polyval_clmulni ghash_clmulni_intel aesni_intel rapl input_leds psmouse serio_raw i2c_piix4 vga16fb bochs vgastate i2c_smbus floppy mac_hid qemu_fw_cfg pata_acpi sch_fq_codel rbd msr parport_pc ppdev lp parport efi_pstore [ 408.072304] CPU: 1 UID: 0 PID: 392 Comm: kworker/1:3 Not tainted 6.17.0-rc7+ [ 408.072307] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-5.fc42 04/01/2014 [ 408.072310] Workqueue: ceph-msgr ceph_con_workfn [ 408.072314] RIP: 0010:ceph_con_v2_try_read+0x4b39/0x72f0 [ 408.072317] Code: c7 c1 20 f0 d4 ae 50 31 d2 48 c7 c6 60 27 d5 ae 48 c7 c7 f8 8e 6f b0 68 60 38 d5 ae e8 00 47 61 fe 48 83 c4 18 e9 ac fc ff ff 0b e9 06 fe ff ff 4c 8b 9d 98 fd ff ff 0f 84 64 e7 ff ff 89 85 [ 408.072319] RSP: 0018:ffff88811c3e7a30 EFLAGS: 00010246 [ 408.072322] RAX: ffffed1024874c6f RBX: ffffea00042c2b40 RCX: 0000000000000f38 [ 408.072324]

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.11-1 (forky)linux 6.17.11-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 6.6.17 < 6.6.1196.6.119
linuxlinux>= 6.7.5 < 6.86.8
linuxlinux>= 8e46a2d068c92a905d01cbb018b00d66991585ab < 47144748fbf12068ba4b82512098fe1ac748a2e947144748fbf12068ba4b82512098fe1ac748a2e9
linuxlinux>= 8e46a2d068c92a905d01cbb018b00d66991585ab < 7d1b7de853f7d1eefd6d22949bcefc0c251867277d1b7de853f7d1eefd6d22949bcefc0c25186727
linuxlinux>= 8e46a2d068c92a905d01cbb018b00d66991585ab < 43962db4a6f593903340c85591056a0cef812dfd43962db4a6f593903340c85591056a0cef812dfd
linuxlinux>= da9c33a70f095d5d55c36d0bfeba969e31de08ae < 5a3f3e39b18705bc578fae58abacc8ef93c151945a3f3e39b18705bc578fae58abacc8ef93c15194
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.11-16.17.11-1
linuxlinux_kernel>= 0 < 6.6.1196.6.119
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 6.7.0 < 6.12.616.12.61
linuxlinux_kernel>= 6.8.0 < 6.17.116.17.11
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv7.2HIGH
vendor_msrc7.0HIGH
vendor_redhat5.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.