cbcvebase.
CVE-2025-68300
published 2025-12-16

CVE-2025-68300: In the Linux kernel, the following vulnerability has been resolved: fs/namespace: fix reference leak in grab_requested_mnt_ns lookup_mnt_ns() already takes a…

PriorityP417high7.2
EPSS
0.18%
7.9th percentile
In the Linux kernel, the following vulnerability has been resolved: fs/namespace: fix reference leak in grab_requested_mnt_ns lookup_mnt_ns() already takes a reference on mnt_ns. grab_requested_mnt_ns() doesn't need to take an extra reference.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.11-1 (forky)linux 6.17.11-1 (forky)
linuxlinux>= 6.12.59 < 6.12.616.12.61
linuxlinux>= 6.17.9 < 6.17.116.17.11
linuxlinux>= 78f0e33cd6c939a555aa80dbed2fec6b333a7660 < 7b6dcd9bfd869eee7693e45b1817dac8c56e5f867b6dcd9bfd869eee7693e45b1817dac8c56e5f86
linuxlinux>= 8ff97ade912dcfc5ac1783c4b8d615aacd26fd17 < fe256e59b8e7f126b2464ee32bd9fee131f0a883fe256e59b8e7f126b2464ee32bd9fee131f0a883
linuxlinux>= ba306daa7fa8ae0be5d64c215e9d43a88b4bc8bf < 4a16b2a0c1f033f95f5d0b98b9e40e8bf7c4c2c54a16b2a0c1f033f95f5d0b98b9e40e8bf7c4c2c5
linuxlinux_kernel>= 0 < 6.17.11-16.17.11-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 6.12.59 < 6.12.616.12.61
linuxlinux_kernel>= 6.17.9 < 6.17.116.17.11

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.